cve 2025 40309

  1. Linux Bluetooth SCO UAF CVE-2025-40309: Stable patch prevents kernel crash

    A small, surgical change to the Linux Bluetooth stack closed a reproducible kernel use‑after‑free (UAF) in the SCO connection destructor — a bug that produced KASAN slab traces and host oopses and that has been tracked as CVE‑2025‑40309. The fix is narrowly scoped, straightforward to backport...