CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel's Bluetooth subsystem could lead to a theoretical use-after-free (UAF) condition if a connection is freed while the hci_sync task is executing. This flaw could potentially allow an attacker to exploit memory management issues, leading to system instability or unauthorized access. Organizations utilizing Linux systems with Bluetooth capabilities should prioritize addressing this vulnerability to mitigate potential risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that. Handle NULL hcon, return 0 + do nothing to match the previous behavior.