CVE-2025-40284 - Bluetooth: MGMT: cancel mesh send timer when hdev removed

CVE-2025-40284 - Bluetooth: MGMT: cancel mesh send timer when hdev removed

CVE ID : CVE-2025-40284 Published : Dec. 6, 2025, 10:15 p.m. | 1 hour, 18 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: cancel mesh send timer when hdev removed mesh_send_done timer is not canceled when hdev is removed, which causes crash if the timer triggers after hdev is gone. Cancel the timer when MGMT removes the hdev, like other MGMT timers. Should fix the BUG: sporadically seen by BlueZ test bot (in

CVE Details

Published
Dec. 6, 2025
Affected Product: Linux

Source: Telegram CVE Monitor