Vulnerabilities
CVE-2025-40284 - Bluetooth: MGMT: cancel mesh send timer when hdev removed
CVE ID : CVE-2025-40284 Published : Dec. 6, 2025, 10:15 p.m. | 1 hour, 18 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: cancel mesh send timer when hdev removed mesh_send_done timer is not canceled when hdev is removed, which causes crash if the timer triggers after hdev is gone. Cancel the timer when MGMT removes the hdev, like other MGMT timers. Should fix the BUG: sporadically seen by BlueZ test bot (in
Source: Telegram CVE Monitor