Linux Kernel

severity

5.5

published

A race in the Linux kernel's Bluetooth MGMT interface can cause add_device_complete() to read an hci_conn_params object after a concurrent device-removal operation has freed it. Triggering the flaw requires high local privileges and a successful race, and can disclose a small amount of kernel memory or crash the system.

add_device_complete() performs an hci_conn_params_lookup() and reads
params->flags without holding hci_dev_lock. A concurrent MGMT_OP_REMOVE_DEVICE operation can remove and free the same object between the lookup and dereference. The fix holds hci_dev_lock across the lookup, flag read, and corresponding event emission. The issue is classified as CWE-416.


References

CVSS v3.1

5.5

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS v3.1

5.5

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS v3.1

5.5

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

SAtJa#rItC  lKoDoDk2i3n2gC  aVtG  yEoPu8rK  s2oBf4t4wTaVrQeP  cZrSi9tYiIc1aRl$l5yT.M

request briefing

request briefing

SRt0aArZt1  l0oDoBkNi@n4gR  a2tJ  y%oCu9r$  sBoGfIt9wVaMrOeV  c1r$i4tPiKcIaQlTlPy#.#

request briefing

request briefing

SLtMa1rBt1  lOoQoVkFiCnBgN  a@t%  ySo5uNr0  s0oBf%tTw8aOr2e7  cDrOiXtLi4cGa8l%lOy$.W

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026