{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-40282",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T07:20:57.184Z",
        "datePublished": "2025-12-06T21:51:06.287Z",
        "dateUpdated": "2026-08-05T12:09:12.019Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:09:12.019Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: 6lowpan: reset link-local header on ipv6 recv path\n\nBluetooth 6lowpan.c netdev has header_ops, so it must set link-local\nheader for RX skb, otherwise things crash, eg. with AF_PACKET SOCK_RAW\n\nAdd missing skb_reset_mac_header() for uncompressed ipv6 RX path.\n\nFor the compressed one, it is done in lowpan_header_decompress().\n\nLog: (BlueZ 6lowpan-tester Client Recv Raw - Success)\n------\nkernel BUG at net/core/skbuff.c:212!\nCall Trace:\n<IRQ>\n...\npacket_rcv (net/packet/af_packet.c:2152)\n...\n<TASK>\n__local_bh_enable_ip (kernel/softirq.c:407)\nnetif_rx (net/core/dev.c:5648)\nchan_recv_cb (net/bluetooth/6lowpan.c:294 net/bluetooth/6lowpan.c:359)\n------"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:A - The malicious frame arrives over a Bluetooth LE L2CAP IPSP channel handled by chan_recv_cb()/recv_pkt(), so the attacker must be within BLE radio range of the target.\nAC:L - The attacker fully controls the trigger — the 6lowpan dispatch byte (0x41) selects the vulnerable uncompressed-IPv6 branch deterministically, with no race, no memory-layout dependency, and no retry needed.\nPR:N - The IPSP listening channel is created with sec_level BT_SECURITY_LOW on BDADDR_ANY, and smp_sufficient_security() short-circuits to true for that level, so an unpaired, unauthenticated peer can connect and send the frame.\nUI:N - No victim action is needed; the packet is processed in softirq context on receipt, and the ndisc/eth_hdr() consumer path is driven entirely by the attacker's own frames.\nS:U - The corruption and its consequences stay within the kernel's own security authority — no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - skb_mac_header() resolves to skb->head + 0xFFFF, giving unbounded out-of-bounds reads — eth_hdr(skb)->h_source in ndisc_recv_na() leaks kernel heap bytes into dmesg, and the ~4 GiB skb->data underflow with inflated skb->len exposes arbitrary kernel memory in paths that do not BUG() first.\nI:H - skb_push()/__skb_push() write a wildly out-of-range skb->data and a massively inflated skb->len before any validation; in the generic-XDP path __skb_push() has no bounds check at all, so the corrupted geometry feeds pskb_expand_head()/skb_linearize() and yields out-of-bounds writes.\nA:H - The reported outcome is a hard kernel BUG() in skb_under_panic() at net/core/skbuff.c:212 taken in IRQ/softirq context, which is a fatal exception in interrupt — an immediate, remotely repeatable kernel panic."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/bluetooth/6lowpan.c"
                    ],
                    "versions": [
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "ea46a1d217bc82e01cf3d0424e50ebfe251e34bf",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "973e0271754c77db3e1b6b69adf2de85a79a4c8b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "d566e9a2bfc848941b091ffd5f4e12c4e889d818",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "4ebb90c3c309e6375dc3e841af92e2a039843e62",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "c24ac6cfe4f9a47180a65592c47e7a310d2f9d93",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "11cd7e068381666f842ad41d1cc58eecd0c75237",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "70d84e7c3a44b81020a3c3d650a64c63593405bd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "18722c247023035b9e2e2a08a887adec2a9a6e49",
                            "lessThan": "3b78f50918276ab28fb22eac9aa49401ac436a3b",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/bluetooth/6lowpan.c"
                    ],
                    "versions": [
                        {
                            "version": "3.14",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "3.14",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.302",
                            "lessThanOrEqual": "5.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.247",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.197",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.159",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.117",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.59",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.17.9",
                            "lessThanOrEqual": "6.17.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "5.4.302"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "5.10.247"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "5.15.197"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "6.1.159"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "6.6.117"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "6.12.59"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "6.17.9"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.14",
                                    "versionEndExcluding": "6.18"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/ea46a1d217bc82e01cf3d0424e50ebfe251e34bf"
                },
                {
                    "url": "https://git.kernel.org/stable/c/973e0271754c77db3e1b6b69adf2de85a79a4c8b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d566e9a2bfc848941b091ffd5f4e12c4e889d818"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4ebb90c3c309e6375dc3e841af92e2a039843e62"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c24ac6cfe4f9a47180a65592c47e7a310d2f9d93"
                },
                {
                    "url": "https://git.kernel.org/stable/c/11cd7e068381666f842ad41d1cc58eecd0c75237"
                },
                {
                    "url": "https://git.kernel.org/stable/c/70d84e7c3a44b81020a3c3d650a64c63593405bd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/3b78f50918276ab28fb22eac9aa49401ac436a3b"
                }
            ],
            "title": "Bluetooth: 6lowpan: reset link-local header on ipv6 recv path",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}