CVE-2023-54197

UnknownEPSS 0.19%

Last modified

CVE-2023-54197 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" This reverts commit 1e9ac114c4428fdb7ff4635b45d4f46017e8916f. This patch introduces a possible null-ptr-def problem. Revert it. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" This reverts commit 1e9ac114c4428fdb7ff4635b45d4f46017e8916f. This patch introduces a possible null-ptr-def problem. Revert it. And the fixed bug by this patch have resolved by commit 73f7b171b7c0 ("Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition").

Metrics

EPSS Probability
0.19%

9.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 95eacef5692545f199fae4e52abfbfa273acb351, < 3b4ed52009723f7dfca7a8ca95163bfb441bfb76; >= af4d48754d5517d33bac5e504ff1f1de0808e29e, < 70a104588e3131415e559c06deb834ce259a285a; >= a18fb433ceb56e0787546a9d77056dd0f215e762, < de0ffb5145c9f418ad76f00e58d4b91c680410b2; >= da3d3fdfb4d523c5da30e35a8dd90e04f0fd8962, < 0837d10f6c37a47a0c73bccf1e39513613a2fcc2; >= 8efae2112d910d8e5166dd0a836791b08721eef1, < a789192f366147a0fbb395650079906d1d04e0b9; >= cbf8deacb7053ce3e3fed64b277c6c6989e65bba, < 952030c914b5f2288609efe868537afcff7a3f51; >= c59c65a14e8f7d738429648833f3bb3f9df0513f, < 8f83fa62614c282dd5d1211a0dd99c6a0a515b81; >= 1e9ac114c4428fdb7ff4635b45d4f46017e8916f, < d8d7ce037d9a8f1f0714ece268c4c2c50845bbc3; >= 1e9ac114c4428fdb7ff4635b45d4f46017e8916f, < db2bf510bd5d57f064d9e1db395ed86a08320c54; >= 4.14.312, < 4.14.315; >= 4.19.280, < 4.19.283; >= 5.4.240, < 5.4.243; >= 5.10.177, < 5.10.180; >= 5.15.105, < 5.15.111; >= 6.1.22, < 6.1.28; >= 6.2.9, < 6.2.15
LinuxLinux6.3

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-54197?
In the Linux kernel, the following vulnerability has been resolved: Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" This reverts commit 1e9ac114c4428fdb7ff4635b45d4f46017e8916f. This patch introduces a possible null-ptr-def problem. Revert it. And the fixed bug by this patch have resolved by commit 73f7b171b7c0 ("Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition").
How severe is CVE-2023-54197?
Severity scoring for CVE-2023-54197 is pending analysis. The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2023-54197?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-54197?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST