PT-2025-20629 · Linux+3 · Linux Kernel+3

Published

2023-04-10

·

Updated

2026-02-02

·

CVE-2023-53145

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use after free bug has been identified in the Linux kernel's Bluetooth component, specifically in the btsdio remove function, due to a race condition. This issue arises when the btsdio remove function runs concurrently with an unfinished work, potentially leading to the freeing of hdev while it is still being used in btsdio work. The bug is related to the binding of data->work with btsdio work in the btsdio probe function, which is started in btsdio send frame.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02186
CVE-2023-53145
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:02334-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1
SUSE-SU-2025_02334-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse