VDB
CISA-2023-1989
CISA-2023-1989
PUBLISHED
CVSS 7.1 HIGH
Reported by redhat · Published April 11, 2023
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices.
Risk Scores
CVSS 3.1
7.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Kernel | Linux kernel version prior to Kernel 6.3 RC4 |
| netapp | hci_baseboard_management_controller | h410c, *, h500s |
| n/a | Kernel | *, Linux kernel version prior to Kernel 6.3 RC4 |
| linux | linux_kernel | 0, 0 |
| debian | debian_linux | 5.10.178-3, 5.10.178-3 |
Timeline
- Apr 11, 2023 CVE Published
- Aug 26, 2024 CVE Updated
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Security Advisory