CVE-2023-53374

Source
https://cve.org/CVERecord?id=CVE-2023-53374
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53374.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53374
Downstream
Related
Published
2025-09-18T13:33:20.965Z
Modified
2026-03-20T12:33:07.262593Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bluetooth: hci_conn: fail SCO/ISO via hci_conn_failed if ACL gone early
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hciconn: fail SCO/ISO via hciconn_failed if ACL gone early

Not calling hci_(dis)connect_cfm before deleting conn referred to by a socket generally results to use-after-free.

When cleaning up SCO connections when the parent ACL is deleted too early, use hciconnfailed to do the connection cleanup properly.

We also need to clean up ISO connections in a similar situation when connecting has started but LE Create CIS is not yet sent, so do it too here.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53374.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ca1fd42e7dbfcb34890ffbf1f2f4b356776dab6f
Fixed
397d58007532644b35fad746da48c41161f32a57
Fixed
e94b898463a62b72a2a8b75dea8936bf4db78e00
Fixed
3344d318337d9dca928fd448e966557ec5063f85
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
75e35bd4b7935ceed2aacd82f55940e73bf0b63b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53374.json"