In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix error code in chan_alloc_skb_cb() The chan_alloc_skb_cb() function is supposed to return error pointers on error. Returning NULL will lead to a NULL dereference.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025040350-CVE-2025-22007-40b3@gregkh/T