Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Linux kernel's Bluetooth L2CAP implementation, specifically within the 'l2cap_le_command_rej' function. This vulnerability could potentially be exploited to cause memory corruption.
Exploitation of this vulnerability could lead to memory corruption, allowing for potential arbitrary code execution or causing a system crash.
The vulnerability can be reproduced by sending a Bluetooth L2CAP command rejection that triggers the 'l2cap_le_command_rej' function. The function processes the command but fails to properly manage the lifecycle of a channel reference, leading to a use-after-free condition.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.