Impact
A theoretical use‑after‑free condition exists in the Linux kernel when a Bluetooth connection object could be freed while a synchronization task is still executing. This flaw might allow an attacker to exploit the dangling reference and inject malicious code. The nature of the vulnerability is a classic Use After Free, potentially leading to arbitrary code execution, system takeover, or denial of service.
Affected Systems
The flaw affects the Linux kernel, specifically the Bluetooth HCI layer. No specific kernel release is documented; the issue is present in any version that has not applied the reference commit and subsequent fix. Vendors distribution of the Linux kernel must verify that the kernel version includes the containment of the reference counter change.
Risk and Exploitability
The CVSS score is not available, and the EPSS score is not provided, so the precise risk magnitude cannot be quantified. The flaw is not listed in CISA's KEV catalog and no exploit has been publicly disclosed. However, because a use‑after‑free can be critical in kernel code, the potential impact is high if an attacker can trigger the condition. The likely attack vector would involve sending crafted Bluetooth packets to a vulnerable host when the problematic connection state is active.
OpenCVE Enrichment