Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_conn lookup and field access must be covered by hdev lock in hci_le_remote_conn_param_req_evt, otherwise it’s possible it is freed concurrently. Extend the hci_dev_lock critical section to cover all conn usage. A flaw was found in the Linux kernel’s Bluetooth component. This Use-After-Free (UAF) vulnerability arises from insufficient locking duringhci_conn lookup and access within the hci_le_remote_conn_param_req_evt function. An attacker could potentially exploit this to cause a system crash or execute arbitrary code.
Details
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 12 | Released |
35 kernels
|
| Debian 13 | Planned | — |
| Ubuntu 24.04 | Planned | — |