Dismissed
(max. allowed matches exceeded)
Activity log
- Created & dismissed (max. allowed matches exceeded) suggestion
Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.
References
Affected products
Linux
- ==94bf6380e936339a700c0b3171a49baf512aa70b
- <6.13
- =<*
- <6.15
- ==6.15
- <44fc74069d8988f2825246f9401218e29de2c0ab
- <6.15
- =<7.1.*
- <c53c70ec289ee12f20c4f1b2fbfd151762c01f67
- ==eb8b860e87b296bd1874c79a668081efd00f9754