Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53145— Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition

AI Predicted 5.5 Difficulty: Hard EPSS 0.18% · P8

Possible ATT&CK Techniques 1AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinuxddbaf13e3609442b64abb931ac21527772d87980< 6c3653627397a0d6eab19b20a59423e118985a6baffected
ddbaf13e3609442b64abb931ac21527772d87980< 3efcbf25e5ab4d4ad1b7e6ba0869ff85540e3f6eaffected
ddbaf13e3609442b64abb931ac21527772d87980< a6650d27ab2c12a8ee750f396edb5ac8b4558b2eaffected
ddbaf13e3609442b64abb931ac21527772d87980< 746b363bef41cc159c051c47f9e30800bc6b520daffected
ddbaf13e3609442b64abb931ac21527772d87980< a5c2a467e9e789ae0891de55b766daac52e3b7b3affected
ddbaf13e3609442b64abb931ac21527772d87980< 179c65828593aff1f444e15debd40a477cb23cf4affected
ddbaf13e3609442b64abb931ac21527772d87980< 73f7b171b7c09139eb3c6a5677c200dc1be5f318affected
2.6.24affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-53145

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition In btsdio_probe, the data->work is bound with btsdio_work. It will be started in btsdio_send_frame. If the btsdio_remove runs with a unfinished work, there may be a race condition that hdev is freed but used in btsdio_work. Fix it by canceling the work before do cleanup in btsdio_remove.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于蓝牙btsdio模块存在释放后重用问题,可能导致任意代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux ddbaf13e3609442b64abb931ac21527772d87980 ~ 6c3653627397a0d6eab19b20a59423e118985a6b -
LinuxLinux 2.6.24 -

II. Public POCs for CVE-2023-53145

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53145

登录查看更多情报信息。

Patches & Fixes for CVE-2023-53145 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-53145

No comments yet


Leave a comment