VDB

CISA-2023-1989

CISA-2023-1989 PUBLISHED CVSS 7.1 HIGH

Reported by redhat · Published April 11, 2023

A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
n/aKernelLinux kernel version prior to Kernel 6.3 RC4
netapphci_baseboard_management_controllerh410c, *, h500s
n/aKernel*, Linux kernel version prior to Kernel 6.3 RC4
linuxlinux_kernel0, 0
debiandebian_linux5.10.178-3, 5.10.178-3

Timeline

  • Apr 11, 2023 CVE Published
  • Aug 26, 2024 CVE Updated
  • Apr 26, 2026 Distribution Patch
  • Apr 26, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›