PT-2023-2056 · Linux+6 · Linux Kernel+6

Peng Hui

+1

·

Published

2023-03-20

·

Updated

2025-06-30

·

CVE-2023-28866

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 6.2.8
Description The issue is related to out-of-bounds access in the Linux kernel, specifically in the net/bluetooth/hci sync.c file. This is due to the amp init1[] and amp init2[] arrays not having an intentionally invalid element as supposed. The vulnerability can be exploited by a remote attacker to disclose protected information.
Recommendations For Linux kernel versions through 6.2.8, update to a version later than 6.2.8 to resolve the issue. As a temporary workaround, consider restricting access to the net/bluetooth/hci sync.c module to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2394
ALT-PU-2023-1542
ALT-PU-2023-1650
ALT-PU-2023-7439
ALT-PU-2024-14046
ALT-PU-2024-6818
AZL-25933
BDU:2023-01778
CVE-2023-28866
INFSA-2024_2394
OPENSUSE-SU-2023_2871-1
OPENSUSE-SU-2023_2892-1
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2023:2809-1
SUSE-SU-2023:2871-1
SUSE-SU-2023:2892-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_02173-1
USN-6033-1
USN-6175-1
USN-6186-1

Affected Products

Alt Linux
Almalinux
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu