Impact
A race condition in the Linux kernel’s Bluetooth L2CAP implementation allows a concurrent call to l2cap_sock_cleanup_listen() and l2cap_sock_put_chan() to result in an unsafe lockless read of a channel pointer that may be null. This can trigger a null‑pointer dereference in kernel mode, potentially causing a kernel panic and denying service to the system. The weakness is a classic example of improper synchronization that leads to a null pointer dereference.
Affected Systems
The vulnerability affects the Linux kernel’s Bluetooth stack across all versions that include the buggy L2CAP code. No specific kernel release numbers are listed, so any unpatched Linux kernel running the Bluetooth stack is potentially impacted.
Risk and Exploitability
The CVSS score of 8 indicates a high severity. The EPSS score is below 1%, suggesting current exploitation likelihood is low, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, via crafted Bluetooth L2CAP traffic that triggers the race, potentially allowing an attacker to force a kernel crash from a Bluetooth connection.
OpenCVE Enrichment
Debian DLA
Debian DSA