btsockrecvmsg in net/bluetooth/afbluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a btsock_ioctl race condition.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35478.json"