Impact
In the Linux kernel Bluetooth subsystem, a flaw in the handling of SCO setup context causes the context not to be freed when a command is cancelled. The leaked entry holds a pointer to a Bluetooth connection that can be freed while the context is still queued, resulting in a use‑after‑free situation. An attacker exploiting this flaw could trigger a kernel crash or memory corruption, leading to denial of service.
Affected Systems
The vulnerability affects the Linux kernel Bluetooth stack across all distributions that use the kernel’s buggy implementation; the specific kernel versions are not enumerated in the data, but it applies to any release that contains the unpatched code.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation so far. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via an external Bluetooth device that initiates a SCO setup and then causes it to be cancelled, exercising the faulty cleanup path. Exploit complexity appears low, relying only on normal Bluetooth operations, but the impact is significant if the kernel crashes.
OpenCVE Enrichment
Debian DLA
Debian DSA