CVE-2023-1989
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
2.6.24 < 4.14.326 | affected | ||
4.15 < 4.19.295 | affected | ||
4.20 < 5.4.257 | affected | ||
5.5 < 5.10.195 | affected | ||
5.11 < 5.15.131 | affected | ||
5.16 < 6.1.52 | affected | ||
6.2 < 6.3 | affected | ||
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.18.0-513.5.1.rt7.307.el8_9 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.18.0-513.5.1.el8_9 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 0:4.18.0-372.91.1.el8_6 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 0:4.18.0-477.64.1.el8_8 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-362.8.1.el9_3 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-362.8.1.el9_3 < * | unaffected |
| Red Hat | Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | 0:4.18.0-372.91.1.el8_6 < * | unaffected |
Weaknesses
- CWE-416: Use After Free
Workarounds
This flaw can be mitigated by preventing the affected Generic Bluetooth SDIO driver kernel module from loading during the boot time. Ensure the module is added into the blacklist file.
Refer:
How do I blacklist a kernel module to prevent it from loading automatically?
https://access.redhat.com/solutions/41278
ADP Enrichment
CVE Program Container
Additional References
- https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=f132c2d13088
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
- https://security.netapp.com/advisory/ntap-20230601-0004/
- https://www.debian.org/security/2023/dsa-5492
- https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/errata/RHSA-2023:6583
- https://access.redhat.com/errata/RHSA-2023:6901
- https://access.redhat.com/errata/RHSA-2023:7077
- https://access.redhat.com/errata/RHSA-2024:0724
- https://access.redhat.com/errata/RHSA-2024:4740
- https://access.redhat.com/security/cve/CVE-2023-1989
- https://bugzilla.redhat.com/show_bug.cgi?id=2185945
- https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=f132c2d13088
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.