VYPR
Medium severity5.5NVD Advisory· Published Jul 10, 2025· Updated Jun 17, 2026

CVE-2025-38315

CVE-2025-38315

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel: Check dsbr size from EFI variable

Since the size of struct btintel_dsbr is already known, we can just start there instead of querying the EFI variable size. If the final result doesn't match what we expect also fail. This fixes a stack buffer overflow when the EFI variable is larger than struct btintel_dsbr.

Affected products

64

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.