Impact
The vulnerability is a Use After Free error in the Linux kernel Bluetooth L2CAP subsystem. When a connection is discarded through a timeout, the kernel accesses the l2cap_data structure without holding the proper lock. If the connection is concurrently deleted, the data structure is freed while still being referenced, which can crash the kernel or allow an attacker to execute arbitrary code with kernel privileges. This flaw corresponds to a classic UAF weakness and carries a high severity of CVSS 8.8.
Affected Systems
All Linux kernel builds that include the Bluetooth L2CAP stack are potentially affected, as the vulnerability is present in generic Linux kernel code. No specific version range is supplied in the advisory, so any kernel lacking the fix should be considered vulnerable. Users of distributions that ship customized kernels should verify whether similar code paths exist.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1% suggests exploitation is currently rare and unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating it is not a widely exploited threat. The most likely attack vector is local, involving an attacker who can trigger Bluetooth operations on a system they can control, or possibly a remote entity that can present a spoofed Bluetooth device to cause a race condition. Because the bug requires a timing race, exploitation may require significant effort.
OpenCVE Enrichment