CVE-2025-38250 | Linux Kernel up to 6.12.35/6.15.4/6.16-rc3 Bluetooth include/linux/skbuff.h vhci_flush use after free (EUVD-2025-20811 / Nessus ID 253667)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.35/6.15.4/6.16-rc3. Affected by this vulnerability is the function vhci_flush in the library include/linux/skbuff.h of the component Bluetooth. Executing manipulation can lead to use after free.
This vulnerability is handled as CVE-2025-38250. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.