Impact
A bug in the Linux kernel’s Bluetooth mgmt subsystem dereferences RCU‑protected hci_conn pointers outside safe critical sections, creating a use‑after‑free condition. Exploitation can corrupt kernel memory or crash the system; potential arbitrary code execution is inferred and not confirmed by the description.
Affected Systems
All Linux distributions that use the stock kernel and enable the Bluetooth mgmt interface are potentially affected. No specific version range was supplied, but the issue correlates with recent commits that modify reference counting and locking for hci_conn in mgmt_pending_cmds.
Risk and Exploitability
The CVSS score is 7.8 and the EPSS score is < 1%, so the precise likelihood of exploitation is low but the severity is high. However, because the flaw operates in kernel space and can lead to memory corruption, the potential impact is severe. The vulnerability is not listed in CISA’s KEV catalog, which indicates it has not yet been observed as a widely exploited issue, but the lack of exploit data does not lower the risk of a local attacker.
OpenCVE Enrichment
Debian DLA