Linux Kernel Bluetooth L2CAP Use-After-Free Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel's Bluetooth L2CAP implementation, specifically within the 'l2cap_le_command_rej' function. This vulnerability could potentially be exploited to cause memory corruption.

Impact

Exploitation of this vulnerability could lead to memory corruption, allowing for potential arbitrary code execution or causing a system crash.

Reproduction

The vulnerability can be reproduced by sending a Bluetooth L2CAP command rejection that triggers the 'l2cap_le_command_rej' function. The function processes the command but fails to properly manage the lifecycle of a channel reference, leading to a use-after-free condition.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched.

Added: Sep 16, 2025, 6:11 PM
Updated: Sep 16, 2025, 6:11 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.4
remediation
7.7
relevance
0.5
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.