CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's Bluetooth subsystem, specifically in the hci_unregister_dev() function, which fails to disable timers before freeing the hci_dev structure. This oversight can lead to a use-after-free condition if a timeout occurs during device teardown, potentially allowing an attacker to execute arbitrary code or cause a system crash. Organizations using Linux with Bluetooth capabilities should prioritize patching this vulnerability to mitigate the associated risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() hci_unregister_dev() does not disable cmd_timer and ncmd_timer before the hci_dev structure is freed. If a timeout fires during device teardown, the callback dereferences freed memory (including the hdev->reset function pointer), leading to a use-after-free. Add disable_delayed_work_sync() calls alongside the existing disable_work_sync() calls to ensure both timers are fully quiesced before teardown proceeds.