Junglewise Threat Intelligence

CVE-2023-54210: Linux kernel Bluetooth hci_sync use-after-free in hci_remove_adv_monitor

CVE-2023-54210 · Severity: high · CVSS 7.8 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Bluetooth subsystem contains a use-after-free vulnerability in the advertisement monitor removal function. An attacker with local access could potentially trigger a kernel crash or execute code by causing the kernel to access freed memory when handling Bluetooth advertisement monitor operations. This impacts system availability and the security of any systems relying on the Bluetooth subsystem.

Technical details

The vulnerability is a use-after-free (CWE-416) in the hci_remove_adv_monitor() function in net/bluetooth/hci_core.c. The vulnerable code path occurs when HCI_ADV_MONITOR_EXT_MSFT is enabled: msft_remove_monitor() frees the monitor structure, but subsequently the code attempts to access monitor->handle in a debug print statement (bt_dev_dbg). The root cause is insufficient coordination between the memory freeing operation and the debug logging access. The fix stashes the monitor handle value before calling msft_remove_monitor(), ensuring the debug print uses the saved value instead of accessing the freed structure. Local access to the kernel (e.g., via ioctl or netlink interface) is required to trigger this vulnerability. The patch is available in the Linux kernel stable tree.

Affected products

  • Linux Linux kernel multiple versions (patch available in stable tree)

Timeline

  • 2023-06-30: disclosed
  • 2023-07-27: patched

References

Related threats