Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix potential use-after-free when clear keys Similar to commit c5d2b6fa26b5 ("Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk"). We can not access k after kfree_rcu() call.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.7, < 5.10.195 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/35cc42f04bc49f0656f6840cb7451b3df6049649Patch
- https://git.kernel.org/stable/c/3673952cf0c6cf81b06c66a0b788abeeb02ff3aePatch
- https://git.kernel.org/stable/c/942d8cefb022f384d5424f8b90c7878f3f93726fPatch
- https://git.kernel.org/stable/c/94617b736c25091b60e514e2e7aeafcbbee6b700Patch
- https://git.kernel.org/stable/c/da19f35868dfbecfff4f81166c054d2656cb1be4Patch
- https://git.kernel.org/stable/c/e87da6a0ac6e631454e7da53a76aa9fe44aaa5ddPatch
FAQ
What is CVE-2023-53386?
CVE-2023-53386 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix potential use-after-free when clear keys Similar to commit c5d2b6fa26b5 ("Bluetooth: Fix use-after-free in hci_remo...
How severe is CVE-2023-53386?
CVE-2023-53386 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53386?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.