CVE-2025-38303: Bluetooth: eir: Fix possible crashes on eir_create_adv_data
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: eir: Fix possible crashes on eir_create_adv_data
eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER
without checking if that would fit.
Security readout for executives and security teams
Plain-English summary
A flaw in Linux Bluetooth advertising-data creation can overfill available space when adding flags or transmit-power information, causing crashes. The supplied CVSS rating is 7.8 and indicates a local, low-privileged attacker could potentially affect confidentiality, integrity, and availability without user interaction.
Executive priority
Treat this as a high-priority kernel maintenance issue, especially for Bluetooth-enabled shared systems. It is not supported as an internet-scale or actively exploited emergency. Accelerate vendor-patched kernel deployment while confirming actual Bluetooth exposure and local-user access.
Technical view
The Linux Bluetooth eir_create_adv_data function could add EIR_FLAGS and EIR_TX_POWER fields without first confirming they fit in the destination. The kernel stable commits add the missing capacity handling. The bundle identifies affected Linux kernel releases but does not provide distribution-specific package mappings.
Likely exposure
Exposure is most likely on systems running an affected Linux kernel where Bluetooth functionality and the relevant advertising-data path are available. Prioritise shared endpoints, Bluetooth-enabled appliances, and systems where untrusted users can obtain local low-privileged access. Distribution backports may make version-only assessment unreliable.
Exploitation context
The supplied CVSS vector requires local access and low privileges, with no user interaction. CISA KEV status is false, and the bundle provides no evidence of active exploitation or a public proof of concept. Practical reachability and reliability are not established by these sources.
Researcher notes
The source bundle supplies no CWE and describes possible crashes from missing size checks. Four stable-kernel commits are referenced, suggesting branch-specific fixes. Exact vulnerable ranges and distribution backports remain ambiguous; validate through vendor package provenance rather than comparing only upstream version strings.
Mitigation direction
Install a vendor kernel containing the applicable upstream stable fix or confirmed backport.
Check distribution and device-vendor advisories for fixed package versions.
Prioritise Bluetooth-enabled systems accessible to untrusted local users.
Apply vendor-recommended temporary controls if immediate kernel updating is unavailable.
Validation and detection
Record each system's running kernel build and distribution package revision.
Confirm vendor documentation maps the installed package to an upstream fixing commit.
Verify whether Bluetooth is enabled and the affected advertising path is operational.
After updating, reboot and confirm the fixed kernel is running.
Monitor kernel logs for Bluetooth-related crashes or memory-safety warnings.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-38303 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
5Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.