CVE-2023-1989

Summary

A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices.

Affected Software

VendorProductVersion RangeStatus
2.6.24 < 4.14.326affected
4.15 < 4.19.295affected
4.20 < 5.4.257affected
5.5 < 5.10.195affected
5.11 < 5.15.131affected
5.16 < 6.1.52affected
6.2 < 6.3affected
Red HatRed Hat Enterprise Linux 80:4.18.0-513.5.1.rt7.307.el8_9 < *unaffected
Red HatRed Hat Enterprise Linux 80:4.18.0-513.5.1.el8_9 < *unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support0:4.18.0-372.91.1.el8_6 < *unaffected
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support0:4.18.0-477.64.1.el8_8 < *unaffected
Red HatRed Hat Enterprise Linux 90:5.14.0-362.8.1.el9_3 < *unaffected
Red HatRed Hat Enterprise Linux 90:5.14.0-362.8.1.el9_3 < *unaffected
Red HatRed Hat Virtualization 4 for Red Hat Enterprise Linux 80:4.18.0-372.91.1.el8_6 < *unaffected

Weaknesses

  • CWE-416: Use After Free

Workarounds

This flaw can be mitigated by preventing the affected Generic Bluetooth SDIO driver kernel module from loading during the boot time. Ensure the module is added into the blacklist file.

Refer:  
How do I blacklist a kernel module to prevent it from loading automatically? 
https://access.redhat.com/solutions/41278

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References