Executive brief
A vulnerability in the Linux kernel's Bluetooth subsystem could allow a local user to cause a memory leak. Over time, this could exhaust system memory, leading to a denial-of-service condition where the system becomes unstable or crashes. This affects various versions of the Linux kernel used in servers, workstations, and embedded devices.
Technical details
A memory leak vulnerability (CWE-401) exists in the Linux kernel Bluetooth subsystem within the 'hci_req_sync_complete()' function in 'net/bluetooth/hci_request.c'. The root cause is the failure to free the previous synchronous request state (specifically the socket buffer 'req_skb') before assigning a reference to a new one. A local attacker with low privileges can exploit this to gradually exhaust system memory. The issue has been resolved in multiple stable kernel branches by ensuring 'kfree_skb' is called on the existing request state before a new reference is acquired via 'skb_get'.
Affected products
- Linux Linux Kernel 4.1 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.156, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7
Timeline
- 2024-04-02: other: Patch authored
- 2024-05-20: disclosed: CVE published
References
- https://git.kernel.org/stable/c/45d355a926ab40f3ae7bc0b0a00cb0e3e8a5a810
- https://git.kernel.org/stable/c/4beab84fbb50df3be1d8f8a976e6fe882ca65cb2
- https://git.kernel.org/stable/c/66fab1e120b39f8f47a94186ddee36006fc02ca8
- https://git.kernel.org/stable/c/75193678cce993aa959e7764b6df2f599886dd06
- https://git.kernel.org/stable/c/8478394f76c748862ef179a16f651f752bdafaf0
- https://git.kernel.org/stable/c/89a32741f4217856066c198a4a7267bcdd1edd67
- https://git.kernel.org/stable/c/9ab5e44b9bac946bd49fd63264a08cd1ea494e76