imPC@ndo IT

Tracker / CVE-2023-1989

CVE-2023-1989

High 7.0

A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices.

Affected products and versions

debian debian_linux
linux linux_kernel · 2.6.24 → 4.14.312
linux linux_kernel · 4.15 → 4.19.280
linux linux_kernel · 4.20 → 5.4.240
linux linux_kernel · 5.11 → 5.15.105
linux linux_kernel · 5.16 → 6.1.22
linux linux_kernel · 5.5 → 5.10.177
linux linux_kernel · 6.2 → 6.2.9
netapp h300s
netapp h410c
netapp h410s
netapp h500s
netapp h700s

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References