Impact
A concurrent close operation can free the socket after sco_recv_frame() releases its lock but before the socket state is accessed, leading to a use‑after‑free. This memory corruption may cause kernel crashes or allow an attacker to execute arbitrary kernel code, potentially escalating privileges. The flaw resides in the Bluetooth SCO subsystem of the Linux kernel and requires the vulnerable function to be invoked.
Affected Systems
Linux kernel implementations that contain the vulnerable sco_recv_frame() routine. No specific kernel versions are listed in the CNA data, so any kernel prior to the patch containing this fix is susceptible.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. The likely attack vector is inferred from the description: an attacker must be able to send or interfere with a Bluetooth SCO frame to trigger the use‑after‑free, requiring a Bluetooth connection to the target’s stack.
OpenCVE Enrichment
Debian DLA
Debian DSA