CVE-2023-40283: Use After Free
Published Aug 14, 2023
·Updated
An issue was discovered in l2capsockrelease in net/bluetooth/l2capsock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
Other sources
Linux Kernel could allow a local authenticated attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the l2capsockrelease function in net/bluetooth/l2capsock.c. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition.
— IBM
Affected Software
20 affected componentsFixes available
IBM Security Verify Governance, Identity Manager software component<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager virtual appliance component<=ISVG 10.0.2
Linux Linux kernel<6.4.10
Debian Debian Linux=11.0
Linux Linux kernel>=3.5<4.14.322
Linux Linux kernel>=4.15<4.19.291
Linux Linux kernel>=4.20<5.4.253
Linux Linux kernel>=5.5<5.10.190
Linux Linux kernel>=5.11<5.15.126
Linux Linux kernel>=5.16<6.1.45
Linux Linux kernel>=6.2<6.4.10
Debian Debian Linux=10.0
Debian Debian Linux=12.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Canonical Ubuntu Linux=22.04
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
redhat/Kernel<6.5
6.5
Remediation
Event History
Aug 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·07:23 AM
DescriptionSeverityAffected Software
Jan 20, 2024
Data Sourced
via Launchpad·12:26 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:14 PM
RemedyDescriptionSeverityAffected Software