btsockrecvmsg in net/bluetooth/afbluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a btsock_ioctl race condition.
{ "vanir_signatures": [ { "signature_type": "Function", "digest": { "function_hash": "187492217720623099608119613585452281197", "length": 1032.0 }, "deprecated": false, "target": { "file": "net/bluetooth/af_bluetooth.c", "function": "bt_sock_recvmsg" }, "source": "https://github.com/torvalds/linux/commit/2e07e8348ea454615e268222ae3fc240421be768", "signature_version": "v1", "id": "CVE-2023-51779-3813d09e" }, { "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "280276399709024522348018551179582714801", "130779295627683096920836239505077261874", "313217983473366906620510906060547389228", "287292984138879010215210031100933983689", "213459270736842134230154576064701003844", "86496758508997896678896535628970494297", "320608758186203773536415424177676022242", "129523336188886786713566908229903983477", "232040809948044634610725463850657623174", "155154654980734673030004759050804760583" ] }, "deprecated": false, "target": { "file": "net/bluetooth/af_bluetooth.c" }, "source": "https://github.com/torvalds/linux/commit/2e07e8348ea454615e268222ae3fc240421be768", "signature_version": "v1", "id": "CVE-2023-51779-3d2c73cf" } ] }