CVE-2025-38641

MEDIUM

Linux Kernel - NULL Pointer Dereference in Bluetooth btusb kmalloc Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix potential NULL dereference on kmalloc failure Avoid potential NULL pointer dereference by checking the return value of kmalloc and handling allocation failure properly.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 2.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (8)
linux/Kernel 6.16.0 - 6.16.1linux
Linux/Linux < 6.16
Linux/Linux 6.16
Linux/Linux 6.16.1 - 6.16.*
Linux/Linux 6.17
Linux/Linux 7d70989fcea7f79afe018a7e34d3486406c7a94e - 5029d80bfc30b60ff57c70ccb04e027acb404f6a
Linux/Linux 7d70989fcea7f79afe018a7e34d3486406c7a94e - b505902c66a282dcb01bcdc015aa1fdfaaa075db
linux/linux_kernel 6.16
Published Aug 22, 2025
Tracked Since Feb 18, 2026