CVE-2025-40318: Linux

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once hci_cmd_sync_dequeue_once() does lookup and then cancel the entry under two separate lock sections. Meanwhile, hci_cmd_sync_work() can also delete the same entry, leading to double list_del() and "UAF". Fix this by holding cmd_sync_work_lock across both lookup and cancel, so that the entry cannot be removed concurrently.

Affected products

  • Linux Linux: from 6.1.120, before 6.1.159 (fixed in 6.1.159); from 6.6.51, before 6.6.117 (fixed in 6.6.117); from 6.8.9, before 6.9 (fixed in 6.9); from 6.9, before 6.12.58 (fixed in 6.12.58); from 6.13, before 6.17.8 (fixed in 6.17.8)

Published 2025-12-08. Last modified 2026-07-30.