CVE-2025-40301EPSS p17.5%
CVE-2025-40301CVE-2025-40301
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: validate skb length for unknown CC opcode
In hci_cmd_complete_evt(), if the command complete event has an unknown
opcode, we assume the first byte of the remaining skb->data contains the
return status. However, parameter data has previously been pulled in
hci_event_func(), which may leave the skb empty. If so, using skb->data[0]
for the return status uses un-init memory.
The fix is to check skb->len before using skb->data.
Scoring
| CVSS | 7.6 () |
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| EPSS | 0.27% probability of exploitation · percentile 17.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-30 |