Dismissed
(max. allowed matches exceeded)
Activity log
- Created & dismissed (max. allowed matches exceeded) suggestion
Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.
References
Affected products
Linux
- ==5dd0bd277a0a936708a33ecc447dce77a08cbde6
- <6.9
- ==6.9
- ==d948e1ffa1d40240d5c81af6dcbcb87b39cb8d3c
- <6.9
- =<7.1.*
- <2f5d635ad5906b0235bc0c870e8beba3116e1e98
- <6.7
- <9a77f296aff4b2ca5f2928ab3a3220c82d8b4074
- =<*