CVE-2025-22007 – Linux Bluetooth NULL Dereference Vulnerability

The following table lists the changes that have been made to the
CVE-2025-22007 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Apr. 03, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    Bluetooth: Fix error code in chan_alloc_skb_cb()

    The chan_alloc_skb_cb() function is supposed to return error pointers on
    error. Returning NULL will lead to a NULL dereference.

    Added Reference https://git.kernel.org/stable/c/72d061ee630d0dbb45c2920d8d19b3861c413e54
    Added Reference https://git.kernel.org/stable/c/761b7c36addd22c7e6ceb05caaadc3b062d99faa
    Added Reference https://git.kernel.org/stable/c/788ae2ae4cf484e248b5bc29211c7ac6510e3e92
    Added Reference https://git.kernel.org/stable/c/a78692ec0d1e17a96b09f2349a028878f5b305e4
    Added Reference https://git.kernel.org/stable/c/ecd06ad0823a90b4420c377ef8917e44e23ee841
Share the Post:

Related Posts