In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: reset link-local header on ipv6 recv path Bluetooth… (CVE-2025-40282)
A high severity vulnerability in the Linux kernel's Bluetooth 6lowpan implementation was resolved. The issue involved missing resetting of the link-local header on the IPv6 receive path, which could cause kernel crashes when processing certain raw socket packets. The fix added the missing skb_reset_mac_header() call for uncompressed IPv6 packets to prevent crashes. This vulnerability affects the kernel's network packet handling in Bluetooth 6lowpan and could lead to denial of service due to kernel bugs.
AI Analysis
Technical Summary
CVE-2025-40282 addresses a flaw in the Linux kernel Bluetooth 6lowpan code where the link-local header was not reset on the IPv6 receive path for uncompressed packets. The netdev structure in 6lowpan.c has header_ops requiring the link-local header to be set for received socket buffers (skb). Without this, processing AF_PACKET SOCK_RAW packets could cause kernel crashes (BUG at net/core/skbuff.c:212). The patch added skb_reset_mac_header() in the uncompressed IPv6 RX path, while the compressed path was already handled by lowpan_header_decompress().
Potential Impact
The vulnerability can cause kernel crashes when receiving certain IPv6 packets over Bluetooth 6lowpan, leading to denial of service. The CVSS 3.1 vector indicates the attack requires adjacent network access, low complexity, no privileges, no user interaction, and impacts confidentiality, integrity, and availability with high severity.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel source code by adding the missing skb_reset_mac_header() call. Users and administrators should apply the official Linux kernel updates that include this patch to remediate the issue. Patch status is not explicitly confirmed in the provided data; verify with the vendor or Linux kernel advisory for the exact fixed versions and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: reset link-local header on ipv6 recv path Bluetooth… (CVE-2025-40282)
Description
A high severity vulnerability in the Linux kernel's Bluetooth 6lowpan implementation was resolved. The issue involved missing resetting of the link-local header on the IPv6 receive path, which could cause kernel crashes when processing certain raw socket packets. The fix added the missing skb_reset_mac_header() call for uncompressed IPv6 packets to prevent crashes. This vulnerability affects the kernel's network packet handling in Bluetooth 6lowpan and could lead to denial of service due to kernel bugs.
CVSS v3.1
Score 8.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-40282 addresses a flaw in the Linux kernel Bluetooth 6lowpan code where the link-local header was not reset on the IPv6 receive path for uncompressed packets. The netdev structure in 6lowpan.c has header_ops requiring the link-local header to be set for received socket buffers (skb). Without this, processing AF_PACKET SOCK_RAW packets could cause kernel crashes (BUG at net/core/skbuff.c:212). The patch added skb_reset_mac_header() in the uncompressed IPv6 RX path, while the compressed path was already handled by lowpan_header_decompress().
Potential Impact
The vulnerability can cause kernel crashes when receiving certain IPv6 packets over Bluetooth 6lowpan, leading to denial of service. The CVSS 3.1 vector indicates the attack requires adjacent network access, low complexity, no privileges, no user interaction, and impacts confidentiality, integrity, and availability with high severity.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel source code by adding the missing skb_reset_mac_header() call. Users and administrators should apply the official Linux kernel updates that include this patch to remediate the issue. Patch status is not explicitly confirmed in the provided data; verify with the vendor or Linux kernel advisory for the exact fixed versions and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5r7j-r8w6-f8xc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-40282"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d49c2644c7f8479558
Added to database: 07/30/2026, 15:50:44 UTC
Last enriched: 07/30/2026, 17:39:00 UTC
Last updated: 09/10/2026, 19:26:54 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.