CVE-2023-53145

Updated: 2025-11-19 04:12:13.828553

Description:

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition In btsdio_probe, the data->work is bound with btsdio_work. It will be started in btsdio_send_frame. If the btsdio_remove runs with a unfinished work, there may be a race condition that hdev is freed but used in btsdio_work. Fix it by canceling the work before do cleanup in btsdio_remove.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1765463110 2025-12-11 21:12:13
CentOS 6 ELS kernel 2.6.32 7.8 HIGH In Testing 2025-11-28 16:13:06
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2026:1771078945 2026-02-14 21:12:21
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Already Fixed 2026-01-22 05:45:54
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Needs Triage 2025-11-19 10:11:08
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Already Fixed 2025-11-28 16:27:23
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH In Testing 2025-11-28 16:23:19
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Already Fixed 2025-11-28 16:23:20