CVE-2023-54214

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix potential user-after-free This fixes all instances of which requires to allocate a buffer calling alloc_skb which may release the chan lock and reacquire later which makes it possible that the chan is disconnected in the meantime.

  • Published Dec 30, 2025
  • CVSS 8.8 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2023-54214 at the National Vulnerability Database