Review reviewHigh

CVE-2023-53305

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free Fix potential use-after-free in l2cap_le_command_rej.

CVSS
7.8
EPSS
0.21%
11.5% percentile
CISA KEV
Not listed
Published
2025.09.17
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.21%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free Fix potential use-after-free in l2cap_le_command_rej.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 71fb419724fadab4efdf98210aa3fe053bd81d29 < e76bab1b7afa580cd76362540fc37551ada4359b, >= 71fb419724fadab4efdf98210aa3fe053bd81d29 < 1a40c56e8bff3e424724d78a9a6b3272dd8a371d, >= 71fb419724fadab4efdf98210aa3fe053bd81d29 < fe49aa73cca6608714477b74bfc6874b9db979df, >= 71fb419724fadab4efdf98210aa3fe053bd81d29 < 2958cf9f805b9f0bdc4a761bf6ea281eb8d44f8e, >= 71fb419724fadab4efdf98210aa3fe053bd81d29 < 548a6b64b3c0688f01119a6fcccceb41f8c984e4, >= 71fb419724fadab4efdf98210aa3fe053bd81d29 < 149daab45922ab1ac7f0cbeacab7251a46bf5e63, >= 71fb419724fadab4efdf98210aa3fe053bd81d29 < 255be68150291440657b2cdb09420b69441af3d8, >= 71fb419724fadab4efdf98210aa3fe053bd81d29 < f752a0b334bb95fe9b42ecb511e0864e2768046f, >= 3.14, < 4.14.324, >= 4.15 < 4.19.293, >= 4.20 < 5.4.255, >= 5.5 < 5.10.192, >= 5.11 < 5.15.128, >= 5.16 < 6.1.47, >= 6.2 < 6.4.12
Fixed versions
4.14.324, 4.19.293, 5.4.255, 5.10.192, 5.15.128, 6.1.47, 6.4.12

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2023-53305 — Linux Linux, linux kernel | SECUFOCUS NOW