UBUNTU-CVE-2023-51779
Vulnerability Summary
Timeline
Description
bt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_sock_ioctl race condition.
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- ubuntu•linux
all | < 4.4.0-253.287 | < 4.15.0-224.236 | < 5.4.0-173.191 | < 5.15.0-100.110
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 4.4.0-1130.136 | < 4.4.0-1168.183 | < 4.15.0-1167.180 | < 5.4.0-1120.130 | < 5.15.0-1056.61
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1056.61~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1120.130~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
< 6.5.0-1015.15~22.04.1
- ubuntu•linux-aws-fips
< 4.15.0-2106.112 | all | < 5.4.0-1120.130+fips1 | < 5.15.0-1056.61+fips1
- ubuntu•linux-aws-hwe
< 4.15.0-1167.180~16.04.1
- ubuntu•linux-azure
< 4.15.0-1176.191~14.04.1 | < 4.15.0-1176.191~16.04.1 | all | < 5.4.0-1126.133 | < 5.15.0-1058.66
- ubuntu•linux-azure-4.15
< 4.15.0-1176.191
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1058.66~20.04.2
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1126.133~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
< 6.5.0-1016.16~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | < 5.15.0-1058.66.1 | all
- ubuntu•linux-azure-fde-5.15
all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
< 4.15.0-2085.91 | all | < 5.4.0-1126.133+fips1
- ubuntu•linux-bluefield
< 5.15.0-1037.39 | < 5.4.0-1080.87 | < 5.15.0-1037.39 | all
- ubuntu•linux-fips
< 4.4.0-1100.107 | all | < 4.15.0-1122.133 | < 5.4.0-1094.104 | < 5.15.0-100.110+fips1
- ubuntu•linux-gcp
< 4.15.0-1161.178~16.04.1 | all | < 5.4.0-1124.133 | < 5.15.0-1053.61
- ubuntu•linux-gcp-4.15
< 4.15.0-1161.178
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1053.61~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1124.133~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.2
all
- ubuntu•linux-gcp-6.5
< 6.5.0-1015.15~22.04.1
- ubuntu•linux-gcp-fips
< 4.15.0-2069.74 | all | < 5.4.0-1124.133+fips1 | < 5.15.0-1055.63+fips2
- ubuntu•linux-gke
all | < 5.15.0-1052.57
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.15
all
Showing first 50 affected entries in server-rendered view.
References (20)
- https://ubuntu.com/security/CVE-2023-51779
- https://git.kernel.org/linus/2e07e8348ea454615e268222ae3fc240421be768
- https://ubuntu.com/security/notices/USN-6606-1
- https://ubuntu.com/security/notices/USN-6680-1
- https://ubuntu.com/security/notices/USN-6681-1
- https://ubuntu.com/security/notices/USN-6686-1
- https://ubuntu.com/security/notices/USN-6680-2
- https://ubuntu.com/security/notices/USN-6681-2
- https://ubuntu.com/security/notices/USN-6681-3
- https://ubuntu.com/security/notices/USN-6686-2
- https://ubuntu.com/security/notices/USN-6680-3
- https://ubuntu.com/security/notices/USN-6681-4
- https://ubuntu.com/security/notices/USN-6686-3
- https://ubuntu.com/security/notices/USN-6686-4
- https://ubuntu.com/security/notices/USN-6705-1
- https://ubuntu.com/security/notices/USN-6716-1
- https://ubuntu.com/security/notices/USN-6686-5
- https://www.cve.org/CVERecord?id=CVE-2023-51779
- https://ubuntu.com/security/notices/USN-6739-1
- https://ubuntu.com/security/notices/USN-6740-1