Impact
The problem occurs in the Bluetooth SCO code of the Linux kernel where the socket (sk) is dereferenced without holding the required lock or reference count, leading to a use‑after‑free. An attacker who can trigger the faulty path may cause unstable kernel behavior such as a crash, which could be exploited to crash the system or potentially privilege‑escalate if a kernel exploit can be chained. The description does not confirm a working exploit, but the UAF leaves the kernel in an undefined state when a concurrent close occurs.
Affected Systems
All Linux kernel releases that ship the unpatched Bluetooth SCO implementation are affected, regardless of distribution or custom kernel configuration. Any host running a kernel with Bluetooth enabled is potentially vulnerable, as the CNA product list indicates Linux:Linux with no version constraints.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score is reported as < 1%, suggesting that exploitation is unlikely at present. The use‑after‑free could lead to a kernel panic and is not listed in the CISA KEV catalog, and no public proof of exploitation exists. Since no public proof of exploitation exists, the threat is considered opportunistic and would require a malicious Bluetooth device to initiate a SCO connection that races with a concurrent socket close. Security professionals should treat the vulnerability as a potential denial‑of‑service and possible privilege‑escalation vector until further information becomes available.
OpenCVE Enrichment
Ubuntu USN