Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Add check for mgmt_alloc_skb() in mgmt_device_connected() Add check for the return value of mgmt_alloc_skb() in mgmt_device_connected() to prevent null pointer dereference.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.17, < 6.1.131 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/7841180342c9a0fd97d54f3e62c7369309b5cd84Patch
- https://git.kernel.org/stable/c/7d39387886ffe220323cbed5c155233c3276926bPatch
- https://git.kernel.org/stable/c/bdb1805c248e9694dbb3ffa8867cef2e52cf7261Patch
- https://git.kernel.org/stable/c/d8df010f72b8a32aaea393e36121738bb53ed905Patch
- https://git.kernel.org/stable/c/dc516e66fb28c61b248b393e2ddd63bd7f104969Patch
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
FAQ
What is CVE-2025-21936?
CVE-2025-21936 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Add check for mgmt_alloc_skb() in mgmt_device_connected() Add check for the return value of mgmt_alloc_skb() in mgmt_de...
How severe is CVE-2025-21936?
CVE-2025-21936 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-21936?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.