In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: eir: Fix possible crashes on eircreateadv_data
eircreateadvdata may attempt to add EIRFLAGS and EIRTXPOWER without checking if that would fit.
[
{
"id": "CVE-2025-38303-1a99bcf0",
"target": {
"file": "net/bluetooth/eir.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"7297536326969169197043784021890353192",
"136314097967358649918372118505637529477",
"314887633426267281476603529921680196565",
"19790587078237975324695534878752704261",
"202780399670858789797456957213028923475",
"189970290814594860434903581684425786958",
"314466448258519748627877016604207549698",
"235431232921434556503166841388728977852",
"69860271365135559308154116052497438193",
"322801574992595091175147513642125340356",
"98914876419047615314552309199130259584",
"277099490357228960519204712047717612985"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9db0c27e73b7c8a19384a44af527edfda74ff3d",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-346648d4",
"target": {
"file": "net/bluetooth/hci_sync.c",
"function": "hci_set_adv_data_sync"
},
"digest": {
"length": 493.0,
"function_hash": "279861391795311351582119606099995909548"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9db0c27e73b7c8a19384a44af527edfda74ff3d",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-4ba093b4",
"target": {
"file": "net/bluetooth/eir.h"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"39847307623815924794108285282409581641",
"150816626384070856973030603912545450878",
"327192545578459548005680135282641325086"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2af40d795d3fb0ee5c074b7ac56ab22402aa6e4f",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-636c11f7",
"target": {
"file": "net/bluetooth/hci_sync.c",
"function": "hci_set_ext_adv_data_sync"
},
"digest": {
"length": 804.0,
"function_hash": "141267789619008659171399479160854156753"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2af40d795d3fb0ee5c074b7ac56ab22402aa6e4f",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-66ca4867",
"target": {
"file": "net/bluetooth/hci_sync.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"273760394333951281734618989906472362529",
"21965782209177705005769932950120122328",
"319052900561156225053105484547733273839",
"182011725376973659879800828050926470744",
"297998948363454940636789949656339731663",
"80869912778992461153421188572270967322",
"330223769379615357146468064170058641416",
"190360114821518222209604491381154637526"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2af40d795d3fb0ee5c074b7ac56ab22402aa6e4f",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-6a15a187",
"target": {
"file": "net/bluetooth/hci_sync.c",
"function": "hci_set_adv_data_sync"
},
"digest": {
"length": 493.0,
"function_hash": "279861391795311351582119606099995909548"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2af40d795d3fb0ee5c074b7ac56ab22402aa6e4f",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-6d8197c3",
"target": {
"file": "net/bluetooth/hci_sync.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"273760394333951281734618989906472362529",
"21965782209177705005769932950120122328",
"319052900561156225053105484547733273839",
"182011725376973659879800828050926470744",
"297998948363454940636789949656339731663",
"80869912778992461153421188572270967322",
"330223769379615357146468064170058641416",
"190360114821518222209604491381154637526"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47c03902269aff377f959dc3fd94a9733aa31d6e",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-744d21a5",
"target": {
"file": "net/bluetooth/hci_sync.c",
"function": "hci_set_adv_data_sync"
},
"digest": {
"length": 493.0,
"function_hash": "279861391795311351582119606099995909548"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47c03902269aff377f959dc3fd94a9733aa31d6e",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-7a579c2e",
"target": {
"file": "net/bluetooth/hci_sync.c",
"function": "hci_set_ext_adv_data_sync"
},
"digest": {
"length": 804.0,
"function_hash": "141267789619008659171399479160854156753"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47c03902269aff377f959dc3fd94a9733aa31d6e",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-84955ecd",
"target": {
"file": "net/bluetooth/hci_sync.c",
"function": "hci_set_ext_adv_data_sync"
},
"digest": {
"length": 804.0,
"function_hash": "141267789619008659171399479160854156753"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9db0c27e73b7c8a19384a44af527edfda74ff3d",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-88d063ea",
"target": {
"file": "net/bluetooth/eir.c",
"function": "eir_create_adv_data"
},
"digest": {
"length": 1213.0,
"function_hash": "196103103610510782441087272807503238293"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47c03902269aff377f959dc3fd94a9733aa31d6e",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-8c4f947e",
"target": {
"file": "net/bluetooth/eir.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"7297536326969169197043784021890353192",
"136314097967358649918372118505637529477",
"314887633426267281476603529921680196565",
"19790587078237975324695534878752704261",
"202780399670858789797456957213028923475",
"189970290814594860434903581684425786958",
"314466448258519748627877016604207549698",
"235431232921434556503166841388728977852",
"69860271365135559308154116052497438193",
"322801574992595091175147513642125340356",
"98914876419047615314552309199130259584",
"277099490357228960519204712047717612985"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2af40d795d3fb0ee5c074b7ac56ab22402aa6e4f",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-ac117516",
"target": {
"file": "net/bluetooth/eir.c",
"function": "eir_create_adv_data"
},
"digest": {
"length": 1213.0,
"function_hash": "196103103610510782441087272807503238293"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9db0c27e73b7c8a19384a44af527edfda74ff3d",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-dd556938",
"target": {
"file": "net/bluetooth/hci_sync.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"273760394333951281734618989906472362529",
"21965782209177705005769932950120122328",
"319052900561156225053105484547733273839",
"182011725376973659879800828050926470744",
"297998948363454940636789949656339731663",
"80869912778992461153421188572270967322",
"330223769379615357146468064170058641416",
"190360114821518222209604491381154637526"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9db0c27e73b7c8a19384a44af527edfda74ff3d",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-f2f44ed0",
"target": {
"file": "net/bluetooth/eir.h"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"39847307623815924794108285282409581641",
"150816626384070856973030603912545450878",
"327192545578459548005680135282641325086"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9db0c27e73b7c8a19384a44af527edfda74ff3d",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-f7367026",
"target": {
"file": "net/bluetooth/eir.c",
"function": "eir_create_adv_data"
},
"digest": {
"length": 1213.0,
"function_hash": "196103103610510782441087272807503238293"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2af40d795d3fb0ee5c074b7ac56ab22402aa6e4f",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-f73d5526",
"target": {
"file": "net/bluetooth/eir.h"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"39847307623815924794108285282409581641",
"150816626384070856973030603912545450878",
"327192545578459548005680135282641325086"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47c03902269aff377f959dc3fd94a9733aa31d6e",
"signature_version": "v1"
},
{
"id": "CVE-2025-38303-fdb8f86d",
"target": {
"file": "net/bluetooth/eir.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"7297536326969169197043784021890353192",
"136314097967358649918372118505637529477",
"314887633426267281476603529921680196565",
"19790587078237975324695534878752704261",
"202780399670858789797456957213028923475",
"189970290814594860434903581684425786958",
"314466448258519748627877016604207549698",
"235431232921434556503166841388728977852",
"69860271365135559308154116052497438193",
"322801574992595091175147513642125340356",
"98914876419047615314552309199130259584",
"277099490357228960519204712047717612985"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@47c03902269aff377f959dc3fd94a9733aa31d6e",
"signature_version": "v1"
}
]