PT-2025-52995 · Linux+1 · Linux Kernel+1
Published
2025-12-24
·
Updated
2026-03-24
·
CVE-2023-54038
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel's Bluetooth implementation within the
hci conn component. Specifically, the hci connect sco and hci connect cis functions were returning NULL when a link was unavailable, instead of an error pointer. This could lead to a NULL pointer dereference in functions like sco conn add and iso connect cis when attempting to access members of the NULL hcon pointer. The issue was identified through syzkaller testing. The functions hci connect sco() and hci connect cis() have been modified to return an error pointer instead of NULL.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat