CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel's Bluetooth subsystem could lead to a theoretical use-after-free (UAF) condition if a connection is freed while the hci_sync task is executing. This could potentially allow an attacker to exploit the flaw, impacting systems that rely on Bluetooth functionality. Organizations using Linux-based systems with Bluetooth capabilities should prioritize applying updates to mitigate this risk.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.