CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel affects the Bluetooth management subsystem, specifically in the handling of device unpairing and connection disconnection. The issue arises from improper dereferencing of RCU-protected pointers outside critical sections, which could lead to a use-after-free (UAF) condition. System administrators and developers managing Linux environments with Bluetooth capabilities should prioritize addressing this vulnerability to mitigate potential exploitation risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Take hdev->lock for hci_conn lookup and hci_abort_conn(). Don't use RCU to ensure the conn is fully initialized at this point.