CNNVD-202512-754 Information

CNNVD ID

CNNVD-202512-754

CVE-2025-40284

  • CNNVD Published: 2025-12-06

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于Bluetooth MGMT未取消mesh发送定时器,可能导致释放后重用。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. Linux Kernel had a security loophole, which stemmed from the fact that Bluetooth MGMT had not cancelled the timer sent by Mesh, which could lead to reuse after release.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Linux

Published

2025-12-06

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/2927ff643607eddf4f03d10ef80fe10d977154aa https://git.kernel.org/stable/c/990e6143b0ca0c66f099d67d00c112bf59b30d76 https://git.kernel.org/stable/c/fd62ca5ad136dcf6f5aa308423b299a6be6f54ea https://git.kernel.org/stable/c/7b6b6c077cad0601d62c3c34ab7ce3fb25deda7b https://git.kernel.org/stable/c/55fb52ffdd62850d667ebed842815e072d3c9961 https://access.redhat.com/security/cve/cve-2025-40284 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-40284 https://vigilance.fr/vulnerability/Linux-kernel-multiple-vulnerabilities-dated-08-12-2025-49010

Patch

https://www.kernel.org/

Share on: