Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's Bluetooth subsystem can lead to a NULL pointer dereference. The issue arises in the 'hci_connect_sco' and 'hci_connect_cis' functions, which currently return NULL when there is no link available. This behavior allows a NULL value to be passed to subsequent functions, where it is dereferenced, causing a crash. The vulnerability has been reported by syzkaller.
Exploitation of this vulnerability leads to a NULL pointer dereference, causing a system crash.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.