Red Hat disclosed CVE-2025-39981, a Linux kernel flaw in the Bluetooth management subsystem that can trigger a use-after-free or double-free condition in mgmt_pending handling. The bug was traced to struct mgmt_pending objects being freed while still in use, with a KASAN report identifying a slab use-after-free in mgmt_add_adv_patterns_monitor_sync. Red Hat rated the issue Moderate with a CVSS v3 score of 7.3, warning that a local attacker able to interact with the Bluetooth subsystem could cause memory corruption leading to denial of service or possible privilege escalation.
The weakness maps to CWE-416 (Use After Free), a class of memory-safety bugs that can enable crashes, information disclosure, or arbitrary code execution when freed memory is later referenced. The kernel fix adds mgmt_pending_valid checks and removes commands from the pending list while holding mgmt_pending_lock to prevent TOCTOU-related misuse. Red Hat said fixes were shipped for multiple RHEL 8, 9, and 10 kernel packages, while RHEL 6 was not affected because the vulnerable code is absent; the company also recommended hardening or disabling Bluetooth management interfaces where they are not needed.

Get the actors, campaigns, and ATT&CK mapping behind it.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:22854 to address CVE-2025-39981 in the Red Hat Enterprise Linux 10 kernel.
Red Hat released RHSA-2025:22405 to fix CVE-2025-39981 in the Red Hat Enterprise Linux 9 kernel.
Red Hat made its entry for CVE-2025-39981 public, describing a Linux kernel Bluetooth management flaw that can cause use-after-free or double-free conditions in mgmt_pending handling.
The Linux kernel CVE team announced CVE-2025-39981 as a Bluetooth MGMT use-after-free flaw caused by struct mgmt_pending being freed while still processed. The announcement said the issue was introduced in kernel 5.17 and fixed upstream in Linux 6.16.10 and 6.17.
MITRE recorded updates to the CWE-416 Use After Free entry through CWE version 4.20.
Red Hat released RHSA-2026:21706 for the Red Hat Enterprise Linux 8 kernel and RHSA-2026:21745 for the RHEL 8 kernel-rt, both addressing CVE-2025-39981.
Red Hat released RHSA-2026:10108 to fix CVE-2025-39981 in the Red Hat Enterprise Linux 9.4 Extended Update Support kernel.
Red Hat released RHSA-2026:9644 to address CVE-2025-39981 for the Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions kernel.
Red Hat released RHSA-2026:9512 to fix CVE-2025-39981 for the Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions kernel-rt.
Red Hat released RHSA-2026:0457 to address CVE-2025-39981 in the Red Hat Enterprise Linux 9.6 Extended Update Support kernel.
Red Hat released RHSA-2026:0271 to fix CVE-2025-39981 for the Red Hat Enterprise Linux 10.0 Extended Update Support kernel.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.