Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-1989

Published: April 11, 2023Last modified: September 11, 2023

Description

A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices.

Severity score breakdown

ParameterValue
Base score7
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Notes

Fixed in 6.1.52 (https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=179c65828593aff1f444e15debd40a477cb23cf4)

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlinux-ltsFixed (6.1.54-r0)
Streamlinux-ltsFixed (6.1.54-r0)

References

Published BELL-SAs

ON THIS PAGE