Impact
The flaw is in the Linux kernel’s Bluetooth management subsystem. It allows a use‑after‑free condition by dereferencing RCU‑protected pointers outside proper critical sections during unpair_device or disconnect_sync operations. If exploited, this weakness could corrupt memory, potentially leading to arbitrary code execution or a system crash.
Affected Systems
Any Linux kernel build that includes the Bluetooth stack before the fix in the referenced Git patches is affected. In practice, this includes all kernel versions released prior to the patch, regardless of distribution vendor.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1% suggests exploitation has not been observed widely. Based on the description, the likely attack vector is via the Bluetooth management interface, requiring local interaction with the Bluetooth subsystem. No public exploits have been documented, and the vulnerability is not listed in CISA KEV. However, a successful local exploit could grant privilege escalation, arbitrary code execution, or denial of service.
OpenCVE Enrichment
Debian DLA