In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btmtk: avoid UAF in btmtk_process_coredump
hci_devcd_append may lead to the release of the skb, so it cannot be accessed once it is called.
================================================================== BUG: KASAN: slab-use-after-free in btmtk_process_coredump+0x2a7/0x2d0 [btmtk] Read of size 4 at addr ffff888033cfabb0 by task kworker/0:3/82
CPU: 0 PID: 82 Comm: kworker/0:3 Tainted: G U 6.6.40-lockdep-03464-g1d8b4eb3060e #1 b0b3c1cc0c842735643fb411799d97921d1f688c Hardware name: Google Yaviks_Ufs/Yaviks_Ufs, BIOS Google_Yaviks_Ufs.15217.552.0 05/07/2024 Workqueue: events btusb_rx_work [btusb] Call Trace: <TASK> dump_stack_lvl+0xfd/0x150 print_report+0x131/0x780 kasan_report+0x177/0x1c0 btmtk_process_coredump+0x2a7/0x2d0 [btmtk 03edd567dd71a65958807c95a65db31d433e1d01] btusb_recv_acl_mtk+0x11c/0x1a0 [btusb 675430d1e87c4f24d0c1f80efe600757a0f32bec] btusb_rx_work+0x9e/0xe0 [btusb 675430d1e87c4f24d0c1f80efe600757a0f32bec] worker_thread+0xe44/0x2cc0 kthread+0x2ff/0x3a0 ret_from_fork+0x51/0x80 ret_from_fork_asm+0x1b/0x30 </TASK>
Allocated by task 82: stack_trace_save+0xdc/0x190 kasan_set_track+0x4e/0x80 __kasan_slab_alloc+0x4e/0x60 kmem_cache_alloc+0x19f/0x360 skb_clone+0x132/0xf70 btusb_recv_acl_mtk+0x104/0x1a0 [btusb] btusb_rx_work+0x9e/0xe0 [btusb] worker_thread+0xe44/0x2cc0 kthread+0x2ff/0x3a0 ret_from_fork+0x51/0x80 ret_from_fork_asm+0x1b/0x30
Freed by task 1733: stack_trace_save+0xdc/0x190 kasan_set_track+0x4e/0x80 kasan_save_free_info+0x28/0xb0 ____kasan_slab_free+0xfd/0x170 kmem_cache_free+0x183/0x3f0 hci_devcd_rx+0x91a/0x2060 [bluetooth] worker_thread+0xe44/0x2cc0 kthread+0x2ff/0x3a0 ret_from_fork+0x51/0x80 ret_from_fork_asm+0x1b/0x30
The buggy address belongs to the object at ffff888033cfab40 which belongs to the cache skbuff_head_cache of size 232 The buggy address is located 112 bytes inside of freed 232-byte region [ffff888033cfab40, ffff888033cfac28)
The buggy address belongs to the physical page: page:00000000a174ba93 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x33cfa head:00000000a174ba93 order:1 entire_mapcount:0 nr_pages_mapped:0 pincount:0 anon flags: 0x4000000000000840(slab|head|zone=1) page_type: 0xffffffff() raw: 4000000000000840 ffff888100848a00 0000000000000000 0000000000000001 raw: 0000000000000000 0000000080190019 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected
Memory state around the buggy address: ffff888033cfaa80: fb fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc ffff888033cfab00: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb >ffff888033cfab80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ^ ffff888033cfac00: fb fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc ffff888033cfac80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ==================================================================
Check if we need to call hci_devcd_complete before calling hci_devcd_append. That requires that we check data->cd_info.cnt >= MTK_COREDUMP_NUM instead of data->cd_info.cnt > MTK_COREDUMP_NUM, as we increment data->cd_info.cnt only once the call to hci_devcd_append succeeds.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | Upgrade kernelNo solution existsUpgrade kernel-rt | May 15, 2025 | Dec 27, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1011-gkeopUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-1029-gcpUpgrade linux-image-6.8.0-1029-gcp-64kUpgrade linux-image-6.11.0-21-generic-64kUpgrade linux-image-6.8.0-1027-nvidia-lowlatencyUpgrade linux-image-generic-64kUpgrade linux-image-oracle-lts-24.04Upgrade linux-image-6.8.0-1028-azureUpgrade linux-image-gkeop-6.8Upgrade linux-image-virtual-hwe-22.04Upgrade linux-image-gkeUpgrade linux-image-genericUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-oem-22.04bUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-gkeopUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.8.0-1028-awsUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-59-lowlatencyUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-oem-22.04cUpgrade linux-image-oracle-64kUpgrade linux-image-6.11.0-1010-raspiUpgrade linux-image-6.11.0-1013-oracle-64kUpgrade linux-image-realtimeUpgrade linux-image-6.8.0-1025-oracleUpgrade linux-image-gcpUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-24.04Upgrade linux-image-gcp-lts-24.04Upgrade linux-image-raspi-realtimeUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-6.8.0-1025-ibmUpgrade linux-image-6.8.0-59-genericUpgrade linux-image-aws-lts-24.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-oracleUpgrade linux-image-6.11.0-1011-lowlatency-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-6.8.0-1016-azure-nvidiaUpgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1024-gkeUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1027-nvidiaUpgrade linux-image-6.8.0-1025-oracle-64kUpgrade linux-image-6.11.0-1012-azureUpgrade linux-image-azure-lts-24.04Upgrade linux-image-6.11.0-1013-oracleUpgrade linux-image-6.11.0-1007-realtimeUpgrade linux-image-azure-fdeUpgrade linux-image-lowlatencyUpgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-generic-lpaeUpgrade linux-image-6.11.0-21-genericUpgrade linux-image-oem-22.04aUpgrade linux-image-ibm-classicUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-kvmUpgrade linux-image-6.8.0-59-generic-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.8.0-2023-raspi-realtimeUpgrade linux-image-6.8.0-1027-nvidia-lowlatency-64kUpgrade linux-image-6.11.0-1011-awsUpgrade linux-image-6.8.0-1028-azure-fdeUpgrade linux-image-oem-22.04dUpgrade linux-image-nvidia-6.8Upgrade linux-image-6.11.0-1011-gcp-64kUpgrade linux-image-azure-nvidiaUpgrade linux-image-awsUpgrade linux-image-6.8.0-1028-raspiUpgrade linux-image-6.8.0-1027-nvidia-64kUpgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-azureUpgrade linux-image-gcp-64kUpgrade linux-image-6.8.0-59-lowlatency-64kUpgrade linux-image-6.11.0-1017-oemUpgrade linux-image-6.11.0-1011-lowlatencyUpgrade linux-image-6.8.1-1021-realtimeUpgrade linux-image-6.11.0-1012-azure-fdeUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-6.11.0-1011-gcpUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-1027-oemUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-ibmUpgrade linux-image-raspiUpgrade linux-image-oem-22.04Upgrade linux-image-gcp-64k-lts-24.04 | Mar 28, 2025 | Dec 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub