Executive brief
The Linux kernel's Bluetooth implementation contains a use-after-free vulnerability in the HCI disconnect event handler. When a Bluetooth disconnection fails, the code deletes the connection object without first notifying higher-level protocols (ISO, L2CAP, SCO). These protocols then attempt to access the deleted connection, causing kernel crashes or potential code execution. This affects any system running Linux with Bluetooth connectivity enabled.
Technical details
The vulnerability is a use-after-free in the HCI disconnect command status handler (hci_cs_disconnect). The root cause is that hci_conn_del() is called unconditionally even when the disconnect command fails (status 0x0c), deleting the connection object before the disconnect callback (disconn_cfm) is invoked. Higher-level protocols (ISO, L2CAP, SCO) hold references to the hci_conn without using hci_conn_get(), so they rely on disconn_cfm to clean up properly. When the callback is not called, these protocols continue to use the freed connection object. An attacker with local Bluetooth access or ability to trigger connection failures can cause kernel panic or potentially achieve arbitrary code execution through the use-after-free condition.
Affected products
- Linux Linux kernel up to 6.4.0-rc4 and likely later
Timeline
- 2025-10-07: disclosed
- 2023: advisory