hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-03-31T00:00:00
Updated: 2024-08-02T12:38:25.326Z
Reserved: 2023-03-15T00:00:00
Link: CVE-2023-28464
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-31T16:15:07.557
Modified: 2024-11-21T07:55:08.297
Link: CVE-2023-28464
Redhat