Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-40318— Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once

CVSS 8.8 · High EPSS 0.26% · P18

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinuxf00f36db76eb8fd10d13e80e2590f23b5beaa54d< 0a94f7e017438935c09ef833a1aa908ad9875213affected
1499f79995c7ee58e3bfeeff75f6d1b37dcda881< 932c0a4f77ac13e526fdd5b42914d29c9821d389affected
505ea2b295929e7be2b4e1bc86ee31cb7862fb01< ae76cf6c2c842944c6514c57df54d728f1916553affected
505ea2b295929e7be2b4e1bc86ee31cb7862fb01< 9cd536970192b72257afcdfba0bfc09993e6f19caffected
505ea2b295929e7be2b4e1bc86ee31cb7862fb01< 09b0cd1297b4dbfe736aeaa0ceeab2265f47f772affected
357603f4d396d85fbf0045512efaf1d7f7394ed7affected
6.1.120< 6.1.159affected
6.6.51< 6.6.117affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-40318

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once hci_cmd_sync_dequeue_once() does lookup and then cancel the entry under two separate lock sections. Meanwhile, hci_cmd_sync_work() can also delete the same entry, leading to double list_del() and "UAF". Fix this by holding cmd_sync_work_lock across both lookup and cancel, so that the entry cannot be removed concurrently.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于竞态条件,可能导致释放后重用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f00f36db76eb8fd10d13e80e2590f23b5beaa54d ~ 0a94f7e017438935c09ef833a1aa908ad9875213 -
LinuxLinux 6.9 -

II. Public POCs for CVE-2025-40318

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-40318

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-08 · 82 CVEs total

CVE-2023-537519.8 CRITICALcifs: fix potential use-after-free bugs in TCP_Server_Info::hostname
CVE-2025-403209.8 CRITICALsmb: client: fix potential cfid UAF in smb2_query_info_compound
CVE-2023-537699.3 CRITICALvirt/coco/sev-guest: Double-buffer messages
CVE-2023-537648.8 HIGHwifi: ath12k: Handle lock during peer_id find
CVE-2023-537628.8 HIGHBluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync
CVE-2025-402928.4 HIGHvirtio-net: fix received length check in big packets
CVE-2025-403098.0 HIGHBluetooth: SCO: Fix UAF on sco_conn_free
CVE-2025-403027.8 HIGHmedia: videobuf2: forbid remove_bufs when legacy fileio is active
CVE-2023-537637.8 HIGHRevert "f2fs: fix to do sanity check on extent cache correctly"
CVE-2023-537687.8 HIGHregmap-irq: Fix out-of-bounds access when allocating config buffers
CVE-2025-402977.8 HIGHnet: bridge: fix use-after-free due to MST port state bypass
CVE-2022-506307.8 HIGHmm: hugetlb: fix UAF in hugetlb_handle_userfault
CVE-2022-506237.8 HIGHfpga: prevent integer overflow in dfl_feature_ioctl_set_irq()
CVE-2023-537597.8 HIGHHID: hidraw: fix data race on device refcount
CVE-2025-403177.8 HIGHregmap: slimbus: fix bus_context pointer in regmap init calls
CVE-2025-403197.8 HIGHbpf: Sync pending IRQ work before freeing ring buffer
CVE-2023-537477.8 HIGHvc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF
CVE-2025-403237.8 HIGHfbcon: Set fb_display[i]->mode to NULL when the mode is released
CVE-2023-537537.8 HIGHdrm/amd/display: fix mapping to non-allocated address
CVE-2023-537527.8 HIGHnet: deal with integer overflows in kmalloc_reserve()

Showing top 20 of 82 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-40318

No comments yet


Leave a comment