CVE-2025-38592 is a Linux kernel vulnerability affecting the Bluetooth subsystem, specifically within the hci_devcd_dump function. It arises from a timing issue where dev_coredumpv can free a buffer (hdev->dump.head) before skb_put_data attempts to access it, leading to a vmalloc-out-of-bounds error and system crash. The vulnerability is rated High severity (CVSS 7.1), with a local attack vector and low attack complexity. A successful exploit could lead to a denial of service (system crash) and potentially information disclosure, though the primary impact is system unavailability. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.15, < 6.15.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.16, < 6.16.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.