Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a… (CVE-2025-40213)
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() due to double list_del via mgmt_pending_valid + mgmt_pending_remove. Use DEFINE_FLEX to declare the flexible array right, and don't memcpy outside bounds. As mgmt_pending_valid removes the cmd from list, use mgmt_pending_free, and also report status on error.
AI Analysis
Technical Summary
CVE-2025-40213 is a vulnerability in the Linux kernel Bluetooth MGMT code involving two main issues: a stack-out-of-bounds error in set_mesh_sync caused by memcpy operations on a badly declared on-stack flexible array, and a crash in set_mesh_complete due to double list deletion through mgmt_pending_valid and mgmt_pending_remove. The fix involves using DEFINE_FLEX to correctly declare the flexible array, preventing out-of-bounds memcpy, and ensuring proper list removal and status reporting with mgmt_pending_free. This vulnerability can cause kernel crashes and potentially compromise system integrity.
Potential Impact
The vulnerability allows for stack-out-of-bounds memory access and double list deletion, which can lead to kernel crashes (denial of service) and potentially arbitrary code execution with elevated privileges due to the nature of kernel memory corruption. The CVSS vector indicates local attack complexity with low privileges required and no user interaction, resulting in high confidentiality, integrity, and availability impact.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by correcting the flexible array declaration and list management in the Bluetooth MGMT code. Users should apply the official Linux kernel updates that include this fix. Since no specific patch links or vendor advisories are provided, check the Linux kernel official repositories or vendor advisories for the relevant fixed kernel versions and apply updates accordingly.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a… (CVE-2025-40213)
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() due to double list_del via mgmt_pending_valid + mgmt_pending_remove. Use DEFINE_FLEX to declare the flexible array right, and don't memcpy outside bounds. As mgmt_pending_valid removes the cmd from list, use mgmt_pending_free, and also report status on error.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-40213 is a vulnerability in the Linux kernel Bluetooth MGMT code involving two main issues: a stack-out-of-bounds error in set_mesh_sync caused by memcpy operations on a badly declared on-stack flexible array, and a crash in set_mesh_complete due to double list deletion through mgmt_pending_valid and mgmt_pending_remove. The fix involves using DEFINE_FLEX to correctly declare the flexible array, preventing out-of-bounds memcpy, and ensuring proper list removal and status reporting with mgmt_pending_free. This vulnerability can cause kernel crashes and potentially compromise system integrity.
Potential Impact
The vulnerability allows for stack-out-of-bounds memory access and double list deletion, which can lead to kernel crashes (denial of service) and potentially arbitrary code execution with elevated privileges due to the nature of kernel memory corruption. The CVSS vector indicates local attack complexity with low privileges required and no user interaction, resulting in high confidentiality, integrity, and availability impact.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by correcting the flexible array declaration and list management in the Bluetooth MGMT code. Users should apply the official Linux kernel updates that include this fix. Since no specific patch links or vendor advisories are provided, check the Linux kernel official repositories or vendor advisories for the relevant fixed kernel versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-hxj9-5m9x-pxq2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-40213"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d59c2644c7f847a26e
Added to database: 07/30/2026, 15:50:45 UTC
Last enriched: 07/30/2026, 17:11:28 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.