Answer in brief
CVE-2025-40213 records a Unknown severity vulnerability in Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d71b98f253b079cbadc83266383f26fe7e9e103b <5c19daa93d9af29f1f46251b47e1ea66bcc8d679 || >=302a1f674c00dd5581ab8e493ef44767c5101aab <1c9aca1787e8395a2c59fef20e914467958969c5 || >=302a1f674c00dd5581ab8e493ef44767c5101aab <e8785404de06a69d89dcdd1e9a0b6ea42dc6d327 || 0b60eb04b8524e1b4b3f07fea0d16fda9a677d9a || 87a1f16f07c6c43771754075e08f45b41d237421 || >=6.6.140 <6.7 || >=6.16.10 <6.17 | 5c19daa93d9af29f1f46251b47e1ea66bcc8d679, 1c9aca1787e8395a2c59fef20e914467958969c5, e8785404de06a69d89dcdd1e9a0b6ea42dc6d327, 6.7, 6.17 |
| Linux/Linuxgeneric | 6.17 | Not reported |
Published upstream
Nov 24, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() due to double list_del via mgmt_pending_valid + mgmt_pending_remove. Use DEFINE_FLEX to declare the flexible array right, and don't memcpy outside bounds. As mgmt_pending_valid removes the cmd from list, use mgmt_pending_free, and also report status on error.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-40213 records a Unknown severity vulnerability in Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d71b98f253b079cbadc83266383f26fe7e9e103b <5c19daa93d9af29f1f46251b47e1ea66bcc8d679 || >=302a1f674c00dd5581ab8e493ef44767c5101aab <1c9aca1787e8395a2c59fef20e914467958969c5 || >=302a1f674c00dd5581ab8e493ef44767c5101aab <e8785404de06a69d89dcdd1e9a0b6ea42dc6d327 || 0b60eb04b8524e1b4b3f07fea0d16fda9a677d9a || 87a1f16f07c6c43771754075e08f45b41d237421 || >=6.6.140 <6.7 || >=6.16.10 <6.17 | 5c19daa93d9af29f1f46251b47e1ea66bcc8d679, 1c9aca1787e8395a2c59fef20e914467958969c5, e8785404de06a69d89dcdd1e9a0b6ea42dc6d327, 6.7, 6.17 |
| Linux/Linuxgeneric | 6.17 | Not reported |
Published upstream
Nov 24, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() due to double list_del via mgmt_pending_valid + mgmt_pending_remove. Use DEFINE_FLEX to declare the flexible array right, and don't memcpy outside bounds. As mgmt_pending_valid removes the cmd from list, use mgmt_pending_free, and also report status on error.
Quoted source text, attributed separately from HOL analysis.