Impact
In the Linux kernel Bluetooth subsystem, a race condition involves RCU‑protected pointers accessed outside their critical sections, resulting in a use‑after‑free of a connection structure. This flaw could allow an attacker to dereference freed memory, enabling execution of arbitrary code with kernel privileges or causing a kernel crash.
Affected Systems
All Linux kernels that include the default Bluetooth driver carry the risk; specific affected releases are not enumerated in the available data and should be patched once the fix is released.
Risk and Exploitability
The CVE lacks an assigned CVSS or EPSS score and is not listed in CISA’s KEV catalog, but the UAF nature indicates potential for privilege escalation or denial of service. No public exploitation path is documented; an attacker would need to trigger the race via the Bluetooth stack, making exploitation non‑trivial yet possible for a determined adversary.
OpenCVE Enrichment