Impact
In the Linux kernel Bluetooth L2CAP implementation a use‑after‑free occurs when the channel’s hci_conn is deleted but the l2cap_chan::conn reference remains. Accessing fields such as hci_conn::hdev in l2cap_sock_setsockopt triggers a KASAN crash that results in a kernel panic, effectively denying availability. The flaw provides no remote code execution or privilege escalation; it only causes service disruption for the local system. Based on the description, it is inferred that the kernel crash is caused by dereferencing a dangling pointer after the associated hci_conn has been freed.
Affected Systems
The vulnerability is tied to Linux kernel builds lacking commit b66774b48dd9 that introduced reference counting and locking for L2CAP channels. Devices running older kernels with Bluetooth L2CAP support—such as desktops, servers, mobile devices, and embedded systems—are at risk. The issue is vendor specific to the Linux kernel. It is inferred that any system with an exposed Bluetooth stack using the affected L2CAP code could trigger this crash.
Risk and Exploitability
The CVSS score of 7.8 indicates a medium‑to‑high severity but the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV and cannot be triggered remotely; it requires local interaction with the Bluetooth subsystem, such as an attacker who can invoke setsockopt on a L2CAP socket. Because it only causes a denial of service without elevating privileges, the overall risk is that a compromised or malicious local user could destabilize the system, but it does not present a broader enterprise threat. This assessment is based on the information provided in the CVE description.
OpenCVE Enrichment