CVE-2023-53828
NONE EPSS 10.6%
Published Dec 9, 20256mo ago · Modified Jun 17, 20262w ago
Published Dec 9, 2025 6mo ago
Last Modified Jun 17, 2026 2w ago
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Avoid use-after-free in dbg for hci_add_adv_monitor() KSAN reports use-after-free in hci_add_adv_monitor(). While adding an adv monitor, hci_add_adv_monitor() calls -> msft_add_monitor_pattern() calls -> msft_add_monitor_sync() calls -> msft_le_monitor_advertisement_cb() calls in an error case -> hci_free_adv_monitor() which frees the *moniter. This is referenced by bt_dev_dbg() in hci_add_adv_monitor(). Fix the bt_dev_dbg() by using handle instead of monitor->handle.
Threat Intelligence
EPSS Exploit Probability
10.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
References 4
- git.kernel.org https://git.kernel.org/stable/c/81d8e9f59df63b8358751c1ffed9f1cf5c796909
- git.kernel.org https://git.kernel.org/stable/c/8d66f7ced51cb924bc90278d6a0a26a52877271a
- git.kernel.org https://git.kernel.org/stable/c/a2bcd2b63271a93a695fabbfbf459c603d956d48
- git.kernel.org https://git.kernel.org/stable/c/aafda69d4807f5edf3558c9534be9b911774e63a
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.