Impact
A theoretical use‑after‑free condition exists in the Linux kernel Bluetooth HCI module when a connection object may be freed while a synchronization task is still executing. The flaw was addressed by adding a reference count to the connection, preventing the dangling reference.
Affected Systems
The flaw affects any Linux kernel that has not incorporated the refcount fix in the hci_sync subsystem of the Bluetooth HCI layer. It is not limited to a particular distribution or release; all affected images must verify inclusion of the referenced commits.
Risk and Exploitability
The CVSS score of 8.8 marks the issue as high severity, while the very low EPSS score of less than 1 % indicates a small likelihood of real‑world exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The report highlights a theoretical use‑after‑free but does not describe a known exploitation path.
OpenCVE Enrichment