Impact
The flaw comes from a race condition in the Linux kernel’s Bluetooth L2CAP implementation. When a listening socket is torn down, a concurrent attempt to add a new accept queue entry may reference a parent socket that has already been freed. This leads to a use‑after‑free in kernel space, which an attacker could exploit to cause a kernel crash or gain elevated privileges if they can trigger the race. The vulnerability exploits a lack of proper locking around the socket state and the parent reference, making the kernel’s memory safety dependent on timing.
Affected Systems
This issue affects the generic Linux kernel. No specific kernel release is listed, so any build that contains the unpatched Bluetooth L2CAP code may be vulnerable. The fix has been merged into the upstream source in the commits linked in the advisory, but systems running earlier kernels without that merge are at risk.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low likelihood of current exploitation, and the vulnerability is not recorded in the CISA KEV catalog. The CVSS score of 8 indicates high severity, aligning with the risk of kernel memory corruption. An attacker would need to orchestrate a timed race or manipulate an L2CAP client to trigger the fault, which could result in a denial‑of-service or privilege escalation. The overall risk remains low to moderate until a public exploit is found, but the severity of a successful exploit is substantial.
OpenCVE Enrichment
Debian DLA
Debian DSA