CVE-2023-54197
Last modified
CVE-2023-54197 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" This reverts commit 1e9ac114c4428fdb7ff4635b45d4f46017e8916f. This patch introduces a possible null-ptr-def problem. Revert it. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" This reverts commit 1e9ac114c4428fdb7ff4635b45d4f46017e8916f. This patch introduces a possible null-ptr-def problem. Revert it. And the fixed bug by this patch have resolved by commit 73f7b171b7c0 ("Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition").
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 95eacef5692545f199fae4e52abfbfa273acb351, < 3b4ed52009723f7dfca7a8ca95163bfb441bfb76; >= af4d48754d5517d33bac5e504ff1f1de0808e29e, < 70a104588e3131415e559c06deb834ce259a285a; >= a18fb433ceb56e0787546a9d77056dd0f215e762, < de0ffb5145c9f418ad76f00e58d4b91c680410b2; >= da3d3fdfb4d523c5da30e35a8dd90e04f0fd8962, < 0837d10f6c37a47a0c73bccf1e39513613a2fcc2; >= 8efae2112d910d8e5166dd0a836791b08721eef1, < a789192f366147a0fbb395650079906d1d04e0b9; >= cbf8deacb7053ce3e3fed64b277c6c6989e65bba, < 952030c914b5f2288609efe868537afcff7a3f51; >= c59c65a14e8f7d738429648833f3bb3f9df0513f, < 8f83fa62614c282dd5d1211a0dd99c6a0a515b81; >= 1e9ac114c4428fdb7ff4635b45d4f46017e8916f, < d8d7ce037d9a8f1f0714ece268c4c2c50845bbc3; >= 1e9ac114c4428fdb7ff4635b45d4f46017e8916f, < db2bf510bd5d57f064d9e1db395ed86a08320c54; >= 4.14.312, < 4.14.315; >= 4.19.280, < 4.19.283; >= 5.4.240, < 5.4.243; >= 5.10.177, < 5.10.180; >= 5.15.105, < 5.15.111; >= 6.1.22, < 6.1.28; >= 6.2.9, < 6.2.15 |
| Linux | Linux | 6.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54197?
How severe is CVE-2023-54197?
How do I fix CVE-2023-54197?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-54191In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54192In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54193In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54194In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54195In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54196In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54198In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54199In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54200In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54201In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54202In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54203In the Linux kernel, the following vulnerability has been re…9.1
Are you affected by CVE-2023-54197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
