bt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_sock_ioctl race condition.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3841-1 linux-5.10 security update
Debian DSA Debian DSA DSA-5593-1 linux security update
Ubuntu USN Ubuntu USN USN-6606-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-6680-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6680-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6680-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-6681-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6681-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6681-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6681-4 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-6686-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6686-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6686-3 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-6686-4 Linux kernel (KVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-6686-5 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-6705-1 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-6716-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-6739-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6740-1 Linux kernel vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:rhel_eus:8.8

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-29T18:54:00.210Z

Reserved: 2023-12-25T00:00:00

Link: CVE-2023-51779

cve-icon Vulnrichment

Updated: 2024-08-02T22:48:11.289Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-29T01:42:05.677

Modified: 2024-11-21T08:38:47.327

Link: CVE-2023-51779

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-12-25T00:00:00Z

Links: CVE-2023-51779 - Bugzilla

cve-icon OpenCVE Enrichment

No data.