CVE-2023-31083
Vulnerability Summary
Timeline
Description
An issue was discovered in drivers/bluetooth/hci_ldisc.c in the Linux kernel 6.2. In hci_uart_tty_ioctl, there is a race condition between HCIUARTSETPROTO and HCIUARTGETPROTO. HCI_UART_PROTO_SET is set before hu->proto is set. A NULL pointer dereference may occur.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.33%• Percentile: 26%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- debian•linux
< 5.10.226-1 | < 6.1.112-1 | < 6.5.8-1 | < 6.5.8-1
- debian•linux-6.1
< 6.1.119-1~deb11u1
- ubuntu•linux
all | < 4.4.0-246.280 | < 4.15.0-219.230 | < 5.4.0-166.183 | < 5.15.0-88.98
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 4.4.0-1124.130 | < 4.4.0-1162.177 | < 4.15.0-1162.175 | < 5.4.0-1113.123 | < 5.15.0-1049.54
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1049.54~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1113.123~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
< 6.2.0-1015.15~22.04.1
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-fips
< 4.15.0-2101.107 | all | < 5.4.0-1113.123+fips1
- ubuntu•linux-aws-hwe
< 4.15.0-1162.175~16.04.1
- ubuntu•linux-azure
< 4.15.0-1171.186~14.04.1 | < 4.15.0-1171.186~16.04.1 | all | < 5.4.0-1119.126 | < 5.15.0-1051.59
- ubuntu•linux-azure-4.15
< 4.15.0-1171.186
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1051.59~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1119.126~18.04.2
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.2
< 6.2.0-1016.16~22.04.1
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | < 5.15.0-1051.59.1 | all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
< 6.2.0-1016.16~22.04.1.1
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
< 4.15.0-2080.86 | all | < 5.4.0-1119.126+fips1
- ubuntu•linux-bluefield
all | < 5.4.0-1074.80 | < 5.15.0-1031.33
- ubuntu•linux-fips
< 4.4.0-1094.101 | all | < 4.15.0-1117.128 | < 5.4.0-1088.97
- ubuntu•linux-gcp
< 4.15.0-1156.173~16.04.1 | all | < 5.4.0-1117.126 | < 5.15.0-1046.54
- ubuntu•linux-gcp-4.15
< 4.15.0-1156.173
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1046.54~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1117.126~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.2
< 6.2.0-1018.20~22.04.1
- ubuntu•linux-gcp-6.5
all
- ubuntu•linux-gcp-fips
< 4.15.0-2064.69 | all | < 5.4.0-1117.126+fips1
- ubuntu•linux-gke
all | < 5.15.0-1046.51
Showing first 50 affected entries in server-rendered view.
References (25)
- https://lore.kernel.org/all/CA+UBctC3p49aTgzbVgkSZ2+TQcqq4fPDO7yZitFT5uBPDeCO2g%40mail.gmail.com/
- https://security.netapp.com/advisory/ntap-20230929-0003/
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9c33663af9ad115f90c076a1828129a3fbadea98
- https://bugzilla.suse.com/show_bug.cgi?id=1210780
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
- https://ubuntu.com/security/CVE-2023-31083
- https://lore.kernel.org/all/CA+UBctC3p49aTgzbVgkSZ2+TQcqq4fPDO7yZitFT5uBPDeCO2g@mail.gmail.com/
- https://git.kernel.org/bluetooth/bluetooth-next/c/ff1b86784849
- https://ubuntu.com/security/notices/USN-6439-1
- https://ubuntu.com/security/notices/USN-6440-1
- https://ubuntu.com/security/notices/USN-6440-2
- https://ubuntu.com/security/notices/USN-6439-2
- https://ubuntu.com/security/notices/USN-6440-3
- https://ubuntu.com/security/notices/USN-6462-1
- https://ubuntu.com/security/notices/USN-6464-1
- https://ubuntu.com/security/notices/USN-6465-1
- https://ubuntu.com/security/notices/USN-6466-1
- https://ubuntu.com/security/notices/USN-6465-2
- https://ubuntu.com/security/notices/USN-6462-2
- https://ubuntu.com/security/notices/USN-6465-3
- https://ubuntu.com/security/notices/USN-6516-1
- https://ubuntu.com/security/notices/USN-6520-1
- https://www.cve.org/CVERecord?id=CVE-2023-31083
- https://security-tracker.debian.org/tracker/CVE-2023-31083