CVE-2025-40294
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern() In the parse_adv_monitor_pattern() function, the value of the 'length' variable is currently limited to HCI_MAX_EXT_AD_LENGTH(251). The size of the 'value' array in the mgmt_adv_pattern structure is 31. If the value of 'pattern[i].length' is set in the user space and exceeds 31, the 'patterns[i].value' array can be accessed out of bound when copied. Increasing the size of the 'value' array in the 'mgmt_adv_pattern' structure will break the userspace. Considering this, and to avoid OOB access revert the limits for 'offset' and 'length' back to the value of HCI_MAX_AD_LENGTH. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
Affected versions
Linux kernel versions
6.1.83,
6.6
and later are affected. Fixed in
6.1.159,
6.6.117,
6.12.58,
6.17.8,
6.18
and their respective stable series.
References
The following references provide additional information about CVE-2025-40294 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/3a50d59b3781bc3a4e96533612509546a4c309a7
-
PatchKernel patch commithttps://git.kernel.org/stable/c/4b7d4aa5399b5a64caee639275615c63c008540d
-
PatchKernel patch commithttps://git.kernel.org/stable/c/5f7350ff2b179764a4f40ba4161b60b8aaef857b
Frequently asked questions
-
What is CVE-2025-40294?
CVE-2025-40294 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.1.83 onward and has been patched in 6.1.159, 6.6.117, 6.12.58 and others. CVE-2025-40294 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2025-40294?
Yes — CVE-2025-40294 has been patched. Fixed versions include 6.1.159, 6.6.117, 6.12.58 and others. If you are running Linux kernel 6.1.83 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2025-40294 actively exploited?
No — CVE-2025-40294 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.