---
id: CVE-2023-40283
title: >-
  An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in
  the Linux kernel before 6.4.10
summary: >-
  An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in
  the Linux kernel before 6.4.10. There is a use-after-free because the children
  of an sk are mishandled.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: adp
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-05-10T04:00:08.967057Z'
published: '2023-08-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:06:00.041Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-40283'
references:
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1728137b33c00d5a2b5110ed7aafb42e7c32e4a1
  - url: >-
      https://github.com/torvalds/linux/commit/1728137b33c00d5a2b5110ed7aafb42e7c32e4a1
  - url: 'https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.10'
  - url: 'https://www.debian.org/security/2023/dsa-5480'
    label: DSA-5480
  - url: 'https://www.debian.org/security/2023/dsa-5492'
    label: DSA-5492
  - url: >-
      http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.html
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html'
    label: >-
      [debian-lts-announce] 20231019 [SECURITY] [DLA 3623-1] linux-5.10 security
      update
  - url: 'https://security.netapp.com/advisory/ntap-20231020-0007/'
  - url: >-
      http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html
  - url: 'https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html'
    label: >-
      [debian-lts-announce] 20240111 [SECURITY] [DLA 3710-1] linux security
      update
tags:
  - cve.org
epss: 0.0055
epssPercentile: 0.43639
ingestedAt: '2026-09-18T15:44:31.588Z'
---

## Overview

An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
