CVE-2023-40283

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Aug 14, 2023
Updated: Jan 11, 2024
CWE ID 416

Summary

CVE-2023-40283 is a use-after-free vulnerability affecting the Linux kernel version before 6.4.10 in the net/bluetooth/l2cap_sock.c file. Specifically, an issue was discovered with the l2cap_sock_release function, which fails to properly manage the children of an sk (socket), leading to memory being freed prematurely and subsequently used again. Attackers could exploit this issue to execute arbitrary code or cause a denial-of-service condition. System administrators are advised to upgrade to the patched kernel version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share