{"id":"CVE-2023-1989","title":"A use-after-free flaw was found in btsdio_remove in drivers\\bluetooth\\btsdio.c in the Linux Kernel","summary":"A use-after-free flaw was found in btsdio_remove in drivers\\bluetooth\\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices.","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 2.6.24, < 4.14.312","linux_kernel >= 4.15, < 4.19.280","linux_kernel >= 4.20, < 5.4.240","linux_kernel >= 5.5, < 5.10.177","linux_kernel >= 5.11, < 5.15.105","linux_kernel >= 5.16, < 6.1.22","linux_kernel >= 6.2, < 6.2.9","h300s","h410c","h410s","h500s","h700s","debian_linux = 10.0","debian_linux = 12.0"],"patched":["linux_kernel 6.2.9"],"published":"2023-04-11","updated":"2026-10-01","sourceUpdated":"2026-10-01T11:17:14.277","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-1989","references":[{"url":"https://access.redhat.com/errata/RHSA-2023:6583","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:6901","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7077","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0724","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:4740","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2023-1989","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2185945","label":"secalert@redhat.com"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=f132c2d13088","label":"secalert@redhat.com"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=f132c2d13088","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230601-0004/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2023/dsa-5492","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2024-05-10T04:00:19.103887Z"},"epss":0.00387,"epssPercentile":0.30186,"ingestedAt":"2026-10-01T11:42:53.790Z","slug":"CVE-2023-1989","body":"## Overview\n\nA use-after-free flaw was found in btsdio_remove in drivers\\bluetooth\\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices.\n\n## Affected\n\n- `linux_kernel >= 2.6.24, < 4.14.312`\n- `linux_kernel >= 4.15, < 4.19.280`\n- `linux_kernel >= 4.20, < 5.4.240`\n- `linux_kernel >= 5.5, < 5.10.177`\n- `linux_kernel >= 5.11, < 5.15.105`\n- `linux_kernel >= 5.16, < 6.1.22`\n- `linux_kernel >= 6.2, < 6.2.9`\n- `h300s`\n- `h410c`\n- `h410s`\n- `h500s`\n- `h700s`\n- `debian_linux = 10.0`\n- `debian_linux = 12.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.2.9`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}