{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-38117",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T04:51:23.986Z",
        "datePublished": "2025-07-03T08:35:25.060Z",
        "dateUpdated": "2026-08-23T12:45:21.364Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-23T12:45:21.364Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Protect mgmt_pending list with its own lock\n\nThis uses a mutex to protect from concurrent access of mgmt_pending\nlist which can cause crashes like:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\nRead of size 2 at addr ffff0000c48885b2 by task syz.4.334/7318\n\nCPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 Not tainted 6.15.0-rc7-syzkaller-g187899f4124a #0 PREEMPT\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C)\n __dump_stack+0x30/0x40 lib/dump_stack.c:94\n dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120\n print_address_description+0xa8/0x254 mm/kasan/report.c:408\n print_report+0x68/0x84 mm/kasan/report.c:521\n kasan_report+0xb0/0x110 mm/kasan/report.c:634\n __asan_report_load2_noabort+0x20/0x2c mm/kasan/report_generic.c:379\n hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\n mgmt_pending_find+0x7c/0x140 net/bluetooth/mgmt_util.c:223\n pending_find net/bluetooth/mgmt.c:947 [inline]\n remove_adv_monitor+0x44/0x1a4 net/bluetooth/mgmt.c:5445\n hci_mgmt_cmd+0x780/0xc00 net/bluetooth/hci_sock.c:1712\n hci_sock_sendmsg+0x544/0xbb0 net/bluetooth/hci_sock.c:1832\n sock_sendmsg_nosec net/socket.c:712 [inline]\n __sock_sendmsg net/socket.c:727 [inline]\n sock_write_iter+0x25c/0x378 net/socket.c:1131\n new_sync_write fs/read_write.c:591 [inline]\n vfs_write+0x62c/0x97c fs/read_write.c:684\n ksys_write+0x120/0x210 fs/read_write.c:736\n __do_sys_write fs/read_write.c:747 [inline]\n __se_sys_write fs/read_write.c:744 [inline]\n __arm64_sys_write+0x7c/0x90 fs/read_write.c:744\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nAllocated by task 7037:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x44/0x54 mm/kasan/generic.c:562\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x9c/0xb4 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4327 [inline]\n __kmalloc_noprof+0x2fc/0x4c8 mm/slub.c:4339\n kmalloc_noprof include/linux/slab.h:909 [inline]\n sk_prot_alloc+0xc4/0x1f0 net/core/sock.c:2198\n sk_alloc+0x44/0x3ac net/core/sock.c:2254\n bt_sock_alloc+0x4c/0x300 net/bluetooth/af_bluetooth.c:148\n hci_sock_create+0xa8/0x194 net/bluetooth/hci_sock.c:2202\n bt_sock_create+0x14c/0x24c net/bluetooth/af_bluetooth.c:132\n __sock_create+0x43c/0x91c net/socket.c:1541\n sock_create net/socket.c:1599 [inline]\n __sys_socket_create net/socket.c:1636 [inline]\n __sys_socket+0xd4/0x1c0 net/socket.c:1683\n __do_sys_socket net/socket.c:1697 [inline]\n __se_sys_socket net/socket.c:1695 [inline]\n __arm64_sys_socket+0x7c/0x94 net/socket.c:1695\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nFreed by task 6607:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_free_info+0x58/0x70 mm/kasan/generic.c:576\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x68/0x88 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline\n---truncated---"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code is reached only through local syscalls — `socket()`/`bind()` on an AF_BLUETOOTH HCI socket bound to HCI_CHANNEL_CONTROL followed by `write()`/`sendmsg()` into `hci_mgmt_cmd()`. Although this is the Bluetooth subsystem, the mgmt interface is a local control API and no over-the-air data from an adjacent peer drives either side of the race.\nAC:L - The attacker controls both sides of the race: one thread issues MGMT_OP_SET_POWERED (whose completion frees the pending command and its socket from the hci_cmd_sync workqueue) while another spams commands such as MGMT_OP_REMOVE_ADV_MONITOR that traverse the same unlocked list. syzbot reproduced this reliably and confirmed the fix on two separate reports.\nPR:L - Binding the control channel requires no capability, and the mgmt commands involved require the HCI_SOCK_TRUSTED flag granted by CAP_NET_ADMIN — a capability held by non-root Bluetooth daemons (e.g. Android's bluetooth UID), which is exactly the low-privileged component an attacker lands in after compromising the remote-facing stack. This matches the CNA precedent for the identical mgmt_pending list bug class (CVE-2026-31511).\nUI:N - The attacker triggers the race entirely from its own threads via socket writes; no victim action, mount, or file open is needed.\nS:U - The use-after-free corrupts kernel heap state within the same kernel security authority, giving local privilege escalation rather than crossing a VM, IOMMU, or sandbox boundary.\nC:H - `hci_sock_get_channel()` reads freed `struct sock` memory, and because `hci_sk_proto` has no dedicated slab the object is allocated with plain kmalloc into a sprayable general-purpose cache; a groomed reclaim lets `pending_find()` return a command with a dangling `sk`, after which `mgmt_cmd_status()`/`mgmt_cmd_complete()` operate on attacker-shaped memory, yielding kernel information disclosure.\nI:H - Concurrent `list_del`/`list_add_tail` on `hdev->mgmt_pending` with no lock corrupts the doubly-linked list, and `list_del` on a stale entry writes attacker-influenced pointers into freed memory; combined with operations on a freed, function-pointer-laden `struct sock`, this provides write and control-flow-hijack primitives.\nA:H - The bug is a KASAN-confirmed slab-use-after-free that oopses the kernel, and the accompanying list corruption and potential double free of the pending command reliably panic the system."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/bluetooth/hci_core.h",
                        "net/bluetooth/hci_core.c",
                        "net/bluetooth/mgmt.c",
                        "net/bluetooth/mgmt_util.c",
                        "net/bluetooth/mgmt_util.h"
                    ],
                    "versions": [
                        {
                            "version": "a380b6cff1a2d2139772e88219d08330f84d0381",
                            "lessThan": "7b5958332f20dc66b19be564c402dbc21b927a81",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a380b6cff1a2d2139772e88219d08330f84d0381",
                            "lessThan": "bdd56875c6926d8009914f427df71797693e90d4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a380b6cff1a2d2139772e88219d08330f84d0381",
                            "lessThan": "4e83f2dbb2bf677e614109df24426c4dded472d4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a380b6cff1a2d2139772e88219d08330f84d0381",
                            "lessThan": "d7882db79135c829a922daf3571f33ea1e056ae3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a380b6cff1a2d2139772e88219d08330f84d0381",
                            "lessThan": "6fe26f694c824b8a4dbf50c635bee1302e3f099c",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/bluetooth/hci_core.h",
                        "net/bluetooth/hci_core.c",
                        "net/bluetooth/mgmt.c",
                        "net/bluetooth/mgmt_util.c",
                        "net/bluetooth/mgmt_util.h"
                    ],
                    "versions": [
                        {
                            "version": "4.1",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.1",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.184",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.94",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.34",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.15.3",
                            "lessThanOrEqual": "6.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.16",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.1",
                                    "versionEndExcluding": "6.1.184"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.1",
                                    "versionEndExcluding": "6.6.94"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.1",
                                    "versionEndExcluding": "6.12.34"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.1",
                                    "versionEndExcluding": "6.15.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.1",
                                    "versionEndExcluding": "6.16"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/7b5958332f20dc66b19be564c402dbc21b927a81"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bdd56875c6926d8009914f427df71797693e90d4"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4e83f2dbb2bf677e614109df24426c4dded472d4"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d7882db79135c829a922daf3571f33ea1e056ae3"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6fe26f694c824b8a4dbf50c635bee1302e3f099c"
                }
            ],
            "title": "Bluetooth: MGMT: Protect mgmt_pending list with its own lock",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}