hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-03-31T00:00:00

Updated: 2024-08-02T12:38:25.326Z

Reserved: 2023-03-15T00:00:00

Link: CVE-2023-28464

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-03-31T16:15:07.557

Modified: 2023-12-22T21:04:49.027

Link: CVE-2023-28464

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-03-28T00:00:00Z

Links: CVE-2023-28464 - Bugzilla