CVE-2025-38315

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Check dsbr size from EFI variable Since the size of struct btintel_dsbr is already known, we can just start there instead of querying the EFI variable size. If the final result doesn't match what we expect also fail. This fixes a stack buffer overflow when the EFI variable is larger than struct btintel_dsbr.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc7:*:*:*:*:*:*

History

18 Nov 2025, 12:55

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/3aa1dc3c9060e335e82e9c182bf3d1db29220b1b - () https://git.kernel.org/stable/c/3aa1dc3c9060e335e82e9c182bf3d1db29220b1b - Patch
References () https://git.kernel.org/stable/c/7b8526bb489780ccc0caffc446ecabec83cfe568 - () https://git.kernel.org/stable/c/7b8526bb489780ccc0caffc446ecabec83cfe568 - Patch
References () https://git.kernel.org/stable/c/9427f6081f37c795a8bd29d0ee72a4da3bd64af8 - () https://git.kernel.org/stable/c/9427f6081f37c795a8bd29d0ee72a4da3bd64af8 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:6.11:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-674
First Time Linux
Linux linux Kernel

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: Bluetooth: btintel: Verificar el tamaño de dsbr desde la variable EFI. Dado que el tamaño de struct btintel_dsbr ya se conoce, podemos empezar por ahí en lugar de consultar el tamaño de la variable EFI. Si el resultado final no coincide con lo esperado, también falla. Esto corrige un desbordamiento del búfer de pila cuando la variable EFI es mayor que struct btintel_dsbr.

10 Jul 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 08:15

Updated : 2025-11-18 12:55


NVD link : CVE-2025-38315

Mitre link : CVE-2025-38315

CVE.ORG link : CVE-2025-38315


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-674

Uncontrolled Recursion