Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-38303

Опубликовано: 10 июл. 2025
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix possible crashes on eir_create_adv_data eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER without checking if that would fit.

Отчет

A vulnerability in eir_create_adv_data() in the Linux Bluetooth stack (introduced in commit 01ce70b0a274) may lead to out-of-bounds memory writes due to the lack of bounds checking when adding EIR fields like EIR_FLAGS and EIR_TX_POWER. This can cause kernel crashes when oversized advertising data is constructed. The bug is fixed by adding explicit size checks before writing into the advertising data buffer. Exploitation leads to a kernel crash (Oops) or memory corruption when the Bluetooth advertising data overflows the target buffer. It does not affect confidentiality or integrity, but can impact availability. Only privileged processes with direct access to Bluetooth HCI configuration interfaces (e.g., kernel threads or root-initiated bluetoothd context) can trigger this code path. Regular unprivileged users cannot invoke it without elevated rights. Although the vulnerability involves memory corruption in kernel space, it occurs in a Bluetooth advertising data generation function that is not directly accessible to unprivileged users. Triggering the flaw requires high privileges (PR:H), and there is no evidence that the corruption can be exploited to gain code execution or affect confidentiality or integrity. The primary impact is a kernel crash, which justifies marking only Availability as High while leaving Confidentiality and Integrity as None.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2379174kernel: Bluetooth: eir: Fix possible crashes on eir_create_adv_data

EPSS

Процентиль: 5%
0.00024
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix possible crashes on eir_create_adv_data eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER without checking if that would fit.

nvd
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix possible crashes on eir_create_adv_data eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER without checking if that would fit.

debian
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: B ...

github
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix possible crashes on eir_create_adv_data eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER without checking if that would fit.

CVSS3: 4.4
fstec
2 месяца назад

Уязвимость функции eir_create_adv_data() ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00024
Низкий

4.4 Medium

CVSS3