« Volver al listado

CVE-2023-53520

Estado: ModificadaMedia (4.7)—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: Fix hci_suspend_sync crash

This patch holds the reference count of the hci_dev object while processing it in hci_suspend_notifier to avoid potential crash caused by the race condition.

Detalles técnicos trazas, registros y código del informe original
If hci_unregister_dev() frees the hci_dev object but hci_suspend_notifier
may still be accessing it, it can cause the program to crash.
Here's the call trace:
  <4>[102152.653246] Call Trace:
  <4>[102152.653254]  hci_suspend_sync+0x109/0x301 [bluetooth]
  <4>[102152.653259]  hci_suspend_dev+0x78/0xcd [bluetooth]
  <4>[102152.653263]  hci_suspend_notifier+0x42/0x7a [bluetooth]
  <4>[102152.653268]  notifier_call_chain+0x43/0x6b
  <4>[102152.653271]  __blocking_notifier_call_chain+0x48/0x69
  <4>[102152.653273]  __pm_notifier_call_chain+0x22/0x39
  <4>[102152.653276]  pm_suspend+0x287/0x57c
  <4>[102152.653278]  state_store+0xae/0xe5
  <4>[102152.653281]  kernfs_fop_write+0x109/0x173
  <4>[102152.653284]  __vfs_write+0x16f/0x1a2
  <4>[102152.653287]  ? selinux_file_permission+0xca/0x16f
  <4>[102152.653289]  ? security_file_permission+0x36/0x109
  <4>[102152.653291]  vfs_write+0x114/0x21d
  <4>[102152.653293]  __x64_sys_write+0x7b/0xdb
  <4>[102152.653296]  do_syscall_64+0x59/0x194
  <4>[102152.653299]  entry_SYSCALL_64_after_hwframe+0x5c/0xc1

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-53520",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9952d90ea2885d7cbf80cd233f694f09a9c0eaec",
              "lessThan": "e1fa25a91091bbed691ba2996a6cee809e3309a2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9952d90ea2885d7cbf80cd233f694f09a9c0eaec",
              "lessThan": "06e2b5ad72b60f90bfe565c201346532e271f484",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9952d90ea2885d7cbf80cd233f694f09a9c0eaec",
              "lessThan": "f9c8ce5d665653e3cf71a76349d41d7a7f7947e6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9952d90ea2885d7cbf80cd233f694f09a9c0eaec",
              "lessThan": "573ebae162111063eedc6c838a659ba628f66a0f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.199",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.55",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.5.5",
              "versionType": "semver",
              "lessThanOrEqual": "6.5.*"
            },
            {
              "status": "unaffected",
              "version": "6.6",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/hci_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-10-01T12:15:56.323",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/06e2b5ad72b60f90bfe565c201346532e271f484",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/573ebae162111063eedc6c838a659ba628f66a0f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e1fa25a91091bbed691ba2996a6cee809e3309a2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f9c8ce5d665653e3cf71a76349d41d7a7f7947e6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix hci_suspend_sync crash\n\nIf hci_unregister_dev() frees the hci_dev object but hci_suspend_notifier\nmay still be accessing it, it can cause the program to crash.\nHere's the call trace:\n  <4>[102152.653246] Call Trace:\n  <4>[102152.653254]  hci_suspend_sync+0x109/0x301 [bluetooth]\n  <4>[102152.653259]  hci_suspend_dev+0x78/0xcd [bluetooth]\n  <4>[102152.653263]  hci_suspend_notifier+0x42/0x7a [bluetooth]\n  <4>[102152.653268]  notifier_call_chain+0x43/0x6b\n  <4>[102152.653271]  __blocking_notifier_call_chain+0x48/0x69\n  <4>[102152.653273]  __pm_notifier_call_chain+0x22/0x39\n  <4>[102152.653276]  pm_suspend+0x287/0x57c\n  <4>[102152.653278]  state_store+0xae/0xe5\n  <4>[102152.653281]  kernfs_fop_write+0x109/0x173\n  <4>[102152.653284]  __vfs_write+0x16f/0x1a2\n  <4>[102152.653287]  ? selinux_file_permission+0xca/0x16f\n  <4>[102152.653289]  ? security_file_permission+0x36/0x109\n  <4>[102152.653291]  vfs_write+0x114/0x21d\n  <4>[102152.653293]  __x64_sys_write+0x7b/0xdb\n  <4>[102152.653296]  do_syscall_64+0x59/0x194\n  <4>[102152.653299]  entry_SYSCALL_64_after_hwframe+0x5c/0xc1\n\nThis patch holds the reference count of the hci_dev object while\nprocessing it in hci_suspend_notifier to avoid potential crash\ncaused by the race condition."
    }
  ],
  "lastModified": "2026-08-04T10:19:10.503",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88F0DAEB-0946-4C4E-B552-34F18C55FDDF",
              "versionEndExcluding": "6.1.55",
              "versionStartIncluding": "5.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CF71E85-DA24-4925-95C5-E5C15DA71AE6",
              "versionEndExcluding": "6.5.5",
              "versionStartIncluding": "6.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}