In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() l2cap_sock_new_connection_cb() returned l2cap_pi(sk)->chan…
Info
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() l2cap_sock_new_connection_cb() returned l2cap_pi(sk)->chan after release_sock(parent). Once the parent lock is dropped the newly enqueued child socket sk is reachable via the accept queue, so another task can accept and free it before the callback dereferences sk, resulting in a use-after-free. Rework the ->new_connection() op so the core, rather than the…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/36da806f7fbaee56ad9e81859deec203f9728700
- https://git.kernel.org/stable/c/6fef032af0092ed5ccb767239a9ac1bc38c08a40
- https://git.kernel.org/stable/c/733e76e74e406c1d1ddc7369420dd8a47f48bb8a
- https://git.kernel.org/stable/c/84e718b6a814edc84159361f9f454a4e92ae91ae
- https://git.kernel.org/stable/c/8c37e4338c801ebb8cee52436c01c41e009f6e87
- https://git.kernel.org/stable/c/b39298044e5534612511a2ff5de03ba5f6e7a820
Timeline
- nvd_ingest NVD