CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the Bluetooth subsystem, specifically the handling of ISO data, where concurrent access can lead to a race condition between memory allocation and deallocation. This can result in use-after-free scenarios, potentially allowing attackers to execute arbitrary code or cause system instability. Organizations using Linux-based systems with Bluetooth capabilities should prioritize addressing this vulnerability to mitigate risks associated with memory corruption and unauthorized access.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero hci_conn::iso_data is accessed and modified without lock or RCU. This leads to a race [Task hdev->workqueue] [Task 2] iso_recv iso_conn_put(conn) conn = LOAD hcon->iso_data iso_conn_free(conn) iso_conn_hold_unless_zero(conn) hcon->iso_data = NULL kfree(conn) kref_get_unless_zero(&conn->ref) /* UAF */ and also to races in iso_conn_add() vs. iso_conn_free(). Fix by adding spinlock hci_conn::proto_lock and using it to guard hci_conn::iso_data.