Linux Kernel Bluetooth SCO Connection Voice Setting Vulnerability Causes Controller Lockup

Vulnerability

A vulnerability in the Linux kernel's Bluetooth implementation has been addressed. The issue arose because a Synchronous Connection-Oriented (SCO) connection could be established without the appropriate voice setting, leading to a lockup of the controller. This problem occurred when SCO support was enabled, but the READ_VOICE_SETTING feature was either unsupported or malfunctioning.

Impact

The vulnerability could cause the Bluetooth controller to become unresponsive or locked up, disrupting any active connections or communications.

Added: Jul 3, 2025, 11:41 AM
Updated: Jul 3, 2025, 11:41 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.