CVE-2025-38304 | Linux Kernel up to 6.1.141/6.6.93/6.12.33/6.15.2/6.16-rc1 Bluetooth eir_get_service_data len null pointer dereference
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.141/6.6.93/6.12.33/6.15.2/6.16-rc1. This affects the function eir_get_service_data of the component Bluetooth. The manipulation of the argument len leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-38304. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.