Impact
A use‑after‑free flaw occurs when a Bluetooth L2CAP connection‑oriented channel (CoC) receives data while the channel is being torn down. The RX work item is submitted to the system workqueue but never cancelled, so the work item can later reference a freed channel object. This leads to memory corruption and, if executed correctly, arbitrary code execution or a denial‑of‑service crash.
Affected Systems
The vulnerability affects the Zephyr RTOS Bluetooth stack, specifically when the configuration enables dynamic L2CAP PSMs (CONFIG_BT_L2CAP_DYNAMIC_CHANNEL) and uses the default Bluetooth RX workqueue. Vendor: Zephyr Project; Product: Zephyr RTOS. Version details are not provided in the advisory.
Risk and Exploitability
According to the CVSS score of 7.5, the flaw is classified as high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. A remote, unauthenticated peer with an established CoC channel can trigger the flaw by sending a data K‑frame followed by an L2CAP Disconnect Request, creating a race condition that results in a use‑after‑free. The likelihood of exploitation is considered significant in environments where the affected configuration is active.
OpenCVE Enrichment