Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF There is a KASAN: slab-use-after-free read in btusb_disconnect(). Calling "usb_driver_release_interface(&btusb_driver, data->intf)" will free the btusb data associated with the interface. The same data is then used later in the function, hence the UAF. Fix by moving the accesses to btusb data to before the data is free'd.

INFO

Published Date :

2025-12-06T21:51:07.409Z

Last Modified :

2025-12-06T21:51:07.409Z

Source :

Linux
AFFECTED PRODUCTS

The following products are affected by CVE-2025-40283 vulnerability.

Vendors Products
Linux
  • Linux Kernel

CVSS Vulnerability Scoring System