CVE-2025-38117 | Linux Kernel up to 6.6.93/6.12.33/6.15.2/6.16-rc1 Bluetooth mgmt_pending use after free (EUVD-2025-19826 / Nessus ID 250054)
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.93/6.12.33/6.15.2/6.16-rc1. Affected by this vulnerability is the function mgmt_pending of the component Bluetooth. This manipulation causes use after free.
This vulnerability is tracked as CVE-2025-38117. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.