Kernel: use after free bug in btsdio_remove due to race condition
Published Apr 11, 2023
7.1
HIGHCVSS 3.1
EPSS 0.39%
Description
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
Configuration 1
- ≥ 2.6.24 · < 4.14.312
- ≥ 4.15 · < 4.19.280
- ≥ 4.20 · < 5.4.240
- ≥ 5.5 · < 5.10.177
- ≥ 5.11 · < 5.15.105
- ≥ 5.16 · < 6.1.22
- ≥ 6.2 · < 6.2.9
Configuration 2
Configuration 3
- 10.0
- 12.0
-
- Version 5.10.178-3StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<6.3+rc4
- Version
-
- Version h300sStatusaffectedConstraints-
- Version h410cStatusaffectedConstraints-
- Version h410sStatusaffectedConstraints-
- Version h500sStatusaffectedConstraints-
- Version h700sStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Debian | Debian Linux | n/a |
| ||||||||||||||||||
| Linux | Linux Kernel | n/a |
| ||||||||||||||||||
| NetApp | Hci Baseboard Management Controller | n/a |
|
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.64.1.el8_8
Fixed · RHSA-2024:4740
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.64.1.el8_8 | Fixed | RHSA-2024:4740 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This flaw can be mitigated by preventing the affected Generic Bluetooth SDIO driver kernel module from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
Red Hat statement
Because successful exploitation of this flaw requires that a system supports SDIO hardware and that an attacker has control over attaching and detaching that hardware, Red Hat assesses the impact of this vulnerability as Moderate.
Red Hat mitigation
This flaw can be mitigated by preventing the affected Generic Bluetooth SDIO driver kernel module from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (CISA ADP) ▾
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 10, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.39% (0.00387) | 30.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.39% (0.00390) | 30.57th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00017) | 2.07th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 16.02th | v3 (v2023.03.01) |
| Jul 16, 2024 | 0.04% (0.00045) | 14.51th | v3 (v2023.03.01) |
| Apr 20, 2023 | 0.04% (0.00043) | 7.03th | v3 (v2023.03.01) |
| Apr 12, 2023 | 0.05% (0.00050) | 17.47th | v3 (v2023.03.01) |
References (15)
- https://access.redhat.com/errata/RHSA-2023:6583 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2023:6901 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2023:7077 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0724 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4740 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-1989 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2185945 issue-trackingx_refsource_REDHATIssue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=f132c2d13088 Mailing ListPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2023-1989
- https://security.netapp.com/advisory/ntap-20230601-0004/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-1989
- https://www.debian.org/security/2023/dsa-5492 vendor-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.