PT-2025-54039 · Linux · Linux Kernel

Published

2023-07-20

·

Updated

2026-03-24

·

CVE-2023-54210

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:M/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the Bluetooth implementation, specifically in the hci sync component. This issue involves a use-after-free condition in the hci remove adv monitor() function, triggered during debugging operations. The problem arises because the monitor structure can be freed by msft remove monitor() before being accessed in bt dev dbg() under the HCI ADV MONITOR EXT MSFT case. The call chain leading to this issue is hci remove adv monitor() -> msft remove monitor() -> msft remove monitor sync() -> msft le cancel monitor advertisement cb() -> hci free adv monitor().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-01317
CVE-2023-54210
SUSE-SU-2026:0263-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0317-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1

Affected Products

Linux Kernel