PT-2023-4425 · Linux+9 · Linux Kernel+9

Hui Peng

+2

·

Published

2023-06-29

·

Updated

2024-08-26

·

CVE-2023-40283

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.4.10
Description The issue is related to the l2cap sock release function in the Linux kernel, specifically in the net/bluetooth/l2cap sock.c file. It involves a use-after-free error because the children of an sk are mishandled. This could potentially allow an attacker to cause a denial of service or have other impacts.
Recommendations For Linux kernel versions prior to 6.4.10, update to version 6.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the l2cap sock release function in net/bluetooth/l2cap sock.c until a patch is available.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0897
ALT-PU-2023-5182
ALT-PU-2023-7439
ALT-PU-2023-8474
ALT-PU-2024-6818
AZL-27936
BDU:2023-04770
CESA-2024_0881
CESA-2024_0897
CVE-2023-40283
DLA-3623-1
DLA-3710-1
DSA-5480-1
DSA-5492-1
LSN-0098-1
LSN-0099-1
OESA-2023-1584
OESA-2023-1585
OESA-2023-1586
OESA-2023-1587
OESA-2023-1588
OPENSUSE-SU-2023_3599-1
OPENSUSE-SU-2023_3599-2
OPENSUSE-SU-2023_3656-1
OPENSUSE-SU-2023_3704-1
OPENSUSE-SU-2023_3704-2
OPENSUSE-SU-2023_3971-1
OPENSUSE-SU-2023_3988-1
OPENSUSE-SU-2023_4058-1
OPENSUSE-SU-2023_4347-1
RHSA-2024:0439
RHSA-2024:0448
RHSA-2024:0461
RHSA-2024:0724
RHSA-2024:0881
RHSA-2024:0897
RHSA-2024:1250
RHSA-2024:1268
RHSA-2024:1269
RHSA-2024:1306
RHSA-2024:1404
RHSA-2024:2582
RHSA-2024:2585
RHSA-2024_0461
RHSA-2024_0881
RHSA-2024_0897
SUSE-SU-2023:3599-1
SUSE-SU-2023:3599-2
SUSE-SU-2023:3601-1
SUSE-SU-2023:3656-1
SUSE-SU-2023:3681-1
SUSE-SU-2023:3705-1
SUSE-SU-2023:3971-1
SUSE-SU-2023:3988-1
SUSE-SU-2023:4030-1
SUSE-SU-2023:4058-1
SUSE-SU-2023:4095-1
SUSE-SU-2023:4142-1
SUSE-SU-2023:4347-1
USN-6343-1
USN-6383-1
USN-6385-1
USN-6386-1
USN-6386-2
USN-6386-3
USN-6387-1
USN-6387-2
USN-6388-1
USN-6396-1
USN-6396-2
USN-6396-3
USN-6466-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu