hciconncleanup in net/bluetooth/hciconn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hciconnhashflush) because of calls to hcidevput and hciconnput. There is a double free that may lead to privilege escalation.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-28464.json"