Security readout for executives and security teams
Plain-English summary
A locking error in the Linux Bluetooth subsystem can make the kernel access memory after it has been freed. This may crash a system or potentially compromise confidentiality and integrity. The supplied evidence demonstrates the memory-safety failure, but does not establish a reliable real-world exploit.
Executive priority
Treat this as a high-priority patching issue for Bluetooth-enabled Linux endpoints, appliances, and exposed operational systems. Expedite validation where untrusted parties can get nearby. Enterprise-wide emergency action is not supported by the supplied evidence because active exploitation is unconfirmed and exact affected package ranges require vendor verification.
Technical view
While processing the HCI number-of-completed-packets event, insufficient locking can allow an HCI connection object to be freed before hci_conn_tx_dequeue reads it. KASAN detected the use-after-free on Linux 6.16.0-rc7. Two stable-kernel correction commits are cited.
Likely exposure
Likely exposure is Linux systems running a vulnerable kernel with Bluetooth enabled. CVSS classifies the attack vector as adjacent, unauthenticated, low complexity, and requiring no user interaction. The sources do not clarify required Bluetooth state, adapter type, pairing, or exact distribution builds.
Exploitation context
The supplied CVSS score is 8.8, reflecting potentially high confidentiality, integrity, and availability impact. The CVE is not listed as KEV, and no supplied source reports active exploitation, a public proof of concept, or confirmed weaponization.
Researcher notes
The evidence is a KASAN slab-use-after-free trace involving concurrent HCI connection cleanup and packet-completion handling. The affected records reference 6.15, 6.16.10, and 6.17, but the flattened bundle does not preserve sufficiently clear range semantics. Verify commit ancestry or distribution package status before declaring exposure. No CWE is supplied.
Mitigation direction
Install vendor-supported kernel updates containing the cited correction commits.
Check distribution and Linux stable guidance to identify fixed packages for each deployed kernel.
Prioritize Bluetooth-enabled systems accessible to untrusted nearby devices or users.
Validation and detection
Inventory running kernel builds and identify systems where Bluetooth is enabled.
Compare each kernel package with vendor advisories and the cited correction commits.
Confirm updated kernels are active after installation and reboot requirements are satisfied.
Review kernel diagnostics for related Bluetooth crashes or use-after-free reports.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-39983 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
3Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.