Impact
The vulnerability resides in the Linux kernel’s Bluetooth RFCOMM implementation. A use‑after‑free occurs when rfcomm_security_cfm() traverses a session’s DLC list without holding rfcomm_mutex, allowing rfcomm_session_del() to free the same session and its DLCs concurrently. The resulting kernel memory corruption can trigger a crash through KASAN or improper updates of freed pointers. The weakness is cataloged as CWE‑825.
Affected Systems
Affected systems are Linux kernel versions that include the Bluetooth RFCOMM stack. All kernel releases prior to the patch that fixed the concurrent teardown race condition are vulnerable. No vendor list restrictions beyond Linux are specified.
Risk and Exploitability
EPSS indicates a very low exploitation probability (<1%). The CVSS score is 8.8, which is not listed in the KEV catalog. The likely attack vector is through the Bluetooth interface, requiring a client that can invoke the security confirmation flow to trigger the race condition. While the exploit requires a concurrent teardown, the absence of a publicly documented exploit reduces immediate risk, but the kernel can still be destabilized. Consequently, the overall risk remains moderate, with a higher priority for systems exposed to Bluetooth traffic.
OpenCVE Enrichment
Debian DSA