{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-38117","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T04:51:23.986Z","datePublished":"2025-07-03T08:35:25.060Z","dateUpdated":"2026-08-23T12:45:21.364Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-23T12:45:21.364Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Protect mgmt_pending list with its own lock\n\nThis uses a mutex to protect from concurrent access of mgmt_pending\nlist which can cause crashes like:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\nRead of size 2 at addr ffff0000c48885b2 by task syz.4.334/7318\n\nCPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 Not tainted 6.15.0-rc7-syzkaller-g187899f4124a #0 PREEMPT\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C)\n __dump_stack+0x30/0x40 lib/dump_stack.c:94\n dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120\n print_address_description+0xa8/0x254 mm/kasan/report.c:408\n print_report+0x68/0x84 mm/kasan/report.c:521\n kasan_report+0xb0/0x110 mm/kasan/report.c:634\n __asan_report_load2_noabort+0x20/0x2c mm/kasan/report_generic.c:379\n hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\n mgmt_pending_find+0x7c/0x140 net/bluetooth/mgmt_util.c:223\n pending_find net/bluetooth/mgmt.c:947 [inline]\n remove_adv_monitor+0x44/0x1a4 net/bluetooth/mgmt.c:5445\n hci_mgmt_cmd+0x780/0xc00 net/bluetooth/hci_sock.c:1712\n hci_sock_sendmsg+0x544/0xbb0 net/bluetooth/hci_sock.c:1832\n sock_sendmsg_nosec net/socket.c:712 [inline]\n __sock_sendmsg net/socket.c:727 [inline]\n sock_write_iter+0x25c/0x378 net/socket.c:1131\n new_sync_write fs/read_write.c:591 [inline]\n vfs_write+0x62c/0x97c fs/read_write.c:684\n ksys_write+0x120/0x210 fs/read_write.c:736\n __do_sys_write fs/read_write.c:747 [inline]\n __se_sys_write fs/read_write.c:744 [inline]\n __arm64_sys_write+0x7c/0x90 fs/read_write.c:744\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nAllocated by task 7037:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x44/0x54 mm/kasan/generic.c:562\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x9c/0xb4 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4327 [inline]\n __kmalloc_noprof+0x2fc/0x4c8 mm/slub.c:4339\n kmalloc_noprof include/linux/slab.h:909 [inline]\n sk_prot_alloc+0xc4/0x1f0 net/core/sock.c:2198\n sk_alloc+0x44/0x3ac net/core/sock.c:2254\n bt_sock_alloc+0x4c/0x300 net/bluetooth/af_bluetooth.c:148\n hci_sock_create+0xa8/0x194 net/bluetooth/hci_sock.c:2202\n bt_sock_create+0x14c/0x24c net/bluetooth/af_bluetooth.c:132\n __sock_create+0x43c/0x91c net/socket.c:1541\n sock_create net/socket.c:1599 [inline]\n __sys_socket_create net/socket.c:1636 [inline]\n __sys_socket+0xd4/0x1c0 net/socket.c:1683\n __do_sys_socket net/socket.c:1697 [inline]\n __se_sys_socket net/socket.c:1695 [inline]\n __arm64_sys_socket+0x7c/0x94 net/socket.c:1695\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nFreed by task 6607:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_free_info+0x58/0x70 mm/kasan/generic.c:576\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x68/0x88 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline\n---truncated---"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached only through local syscalls — `socket()`/`bind()` on an AF_BLUETOOTH HCI socket bound to HCI_CHANNEL_CONTROL followed by `write()`/`sendmsg()` into `hci_mgmt_cmd()`. Although this is the Bluetooth subsystem, the mgmt interface is a local control API and no over-the-air data from an adjacent peer drives either side of the race.\nAC:L - The attacker controls both sides of the race: one thread issues MGMT_OP_SET_POWERED (whose completion frees the pending command and its socket from the hci_cmd_sync workqueue) while another spams commands such as MGMT_OP_REMOVE_ADV_MONITOR that traverse the same unlocked list. syzbot reproduced this reliably and confirmed the fix on two separate reports.\nPR:L - Binding the control channel requires no capability, and the mgmt commands involved require the HCI_SOCK_TRUSTED flag granted by CAP_NET_ADMIN — a capability held by non-root Bluetooth daemons (e.g. Android's bluetooth UID), which is exactly the low-privileged component an attacker lands in after compromising the remote-facing stack. This matches the CNA precedent for the identical mgmt_pending list bug class (CVE-2026-31511).\nUI:N - The attacker triggers the race entirely from its own threads via socket writes; no victim action, mount, or file open is needed.\nS:U - The use-after-free corrupts kernel heap state within the same kernel security authority, giving local privilege escalation rather than crossing a VM, IOMMU, or sandbox boundary.\nC:H - `hci_sock_get_channel()` reads freed `struct sock` memory, and because `hci_sk_proto` has no dedicated slab the object is allocated with plain kmalloc into a sprayable general-purpose cache; a groomed reclaim lets `pending_find()` return a command with a dangling `sk`, after which `mgmt_cmd_status()`/`mgmt_cmd_complete()` operate on attacker-shaped memory, yielding kernel information disclosure.\nI:H - Concurrent `list_del`/`list_add_tail` on `hdev->mgmt_pending` with no lock corrupts the doubly-linked list, and `list_del` on a stale entry writes attacker-influenced pointers into freed memory; combined with operations on a freed, function-pointer-laden `struct sock`, this provides write and control-flow-hijack primitives.\nA:H - The bug is a KASAN-confirmed slab-use-after-free that oopses the kernel, and the accompanying list corruption and potential double free of the pending command reliably panic the system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/bluetooth/hci_core.h","net/bluetooth/hci_core.c","net/bluetooth/mgmt.c","net/bluetooth/mgmt_util.c","net/bluetooth/mgmt_util.h"],"versions":[{"version":"a380b6cff1a2d2139772e88219d08330f84d0381","lessThan":"7b5958332f20dc66b19be564c402dbc21b927a81","status":"affected","versionType":"git"},{"version":"a380b6cff1a2d2139772e88219d08330f84d0381","lessThan":"bdd56875c6926d8009914f427df71797693e90d4","status":"affected","versionType":"git"},{"version":"a380b6cff1a2d2139772e88219d08330f84d0381","lessThan":"4e83f2dbb2bf677e614109df24426c4dded472d4","status":"affected","versionType":"git"},{"version":"a380b6cff1a2d2139772e88219d08330f84d0381","lessThan":"d7882db79135c829a922daf3571f33ea1e056ae3","status":"affected","versionType":"git"},{"version":"a380b6cff1a2d2139772e88219d08330f84d0381","lessThan":"6fe26f694c824b8a4dbf50c635bee1302e3f099c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/bluetooth/hci_core.h","net/bluetooth/hci_core.c","net/bluetooth/mgmt.c","net/bluetooth/mgmt_util.c","net/bluetooth/mgmt_util.h"],"versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","status":"unaffected","versionType":"semver"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.94","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.34","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.15.3","lessThanOrEqual":"6.15.*","status":"unaffected","versionType":"semver"},{"version":"6.16","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.1.184"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.6.94"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.12.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.15.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1","versionEndExcluding":"6.16"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7b5958332f20dc66b19be564c402dbc21b927a81"},{"url":"https://git.kernel.org/stable/c/bdd56875c6926d8009914f427df71797693e90d4"},{"url":"https://git.kernel.org/stable/c/4e83f2dbb2bf677e614109df24426c4dded472d4"},{"url":"https://git.kernel.org/stable/c/d7882db79135c829a922daf3571f33ea1e056ae3"},{"url":"https://git.kernel.org/stable/c/6fe26f694c824b8a4dbf50c635bee1302e3f099c"}],"title":"Bluetooth: MGMT: Protect mgmt_pending list with its own lock","x_generator":{"engine":"bippy-1.2.0"}}}}