PT-2025-13362 · Linux+4 · Linux Kernel+4

Published

2024-04-30

·

Updated

2025-09-29

·

CVE-2023-53016

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A possible deadlock in the Linux kernel's Bluetooth functionality has been identified. The issue occurs when rfcomm sock connect acquires the sk lock and waits for the rfcomm lock, while rfcomm sock release could have the rfcomm lock and attempt to acquire the sk lock, resulting in a deadlock. The vulnerability is related to the rfcomm sk state change function.
Recommendations To resolve the issue, apply the patch that drops the sk lock before calling rfcomm dlc open to avoid the possible deadlock and holds sk's reference count to prevent use-after-free after rfcomm dlc open completes.
Note: Since the provided information does not specify the exact affected versions or a fixed version, it is not possible to provide version-specific recommendations.

Exploit

Fix

DoS

Improper Locking

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-06353
CVE-2023-53016
OPENSUSE-SU-2025_1195-1
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1195-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1195-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Red Os
Suse