cbcvebase.
CVE-2023-53297
published 2025-09-16

CVE-2023-53297: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp conn->chan_lock isn't…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp conn->chan_lock isn't acquired before l2cap_get_chan_by_scid, if l2cap_get_chan_by_scid returns NULL, then 'bad unlock balance' is triggered.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 1351551aa9058e07a20a27a158270cf84fcde621 < 6a27762340ad08643de3bc17fe1646ea489ca2e26a27762340ad08643de3bc17fe1646ea489ca2e2
linuxlinux>= 348d446762e7c70778df8bafbdf3fa0df2123f58 < fd269a0435f8e9943b7a57c5a59688848d42d449fd269a0435f8e9943b7a57c5a59688848d42d449
linuxlinux>= 4.14.313 < 4.14.3164.14.316
linuxlinux>= 4.19.281 < 4.19.2844.19.284
linuxlinux>= 5.10.178 < 5.10.1815.10.181
linuxlinux>= 5.15.108 < 5.15.1135.15.113
linuxlinux>= 5.4.241 < 5.4.2445.4.244
linuxlinux>= 6.1.25 < 6.1.306.1.30
linuxlinux>= 6.2.12 < 6.36.3
linuxlinux>= a2a9339e1c9deb7e1e079e12e27a0265aea8421a < 5134556c9be582793f30695c09d18a26fe1ff2d75134556c9be582793f30695c09d18a26fe1ff2d7
linuxlinux>= a2a9339e1c9deb7e1e079e12e27a0265aea8421a < 25e97f7b1866e6b8503be349eeea44bb52d661ce25e97f7b1866e6b8503be349eeea44bb52d661ce
linuxlinux>= ac6725a634f7e8c0330610a8527f20c730b61115 < 116b9c002c894097adc2b8684db2d1da4229ed46116b9c002c894097adc2b8684db2d1da4229ed46
linuxlinux>= c02421992505c95c7f3c9ad59ee35e22eac60988 < 2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d
linuxlinux>= d9ba36c22a7bb09d6bac4cc2f243eff05da53f43 < 55410a9144c76ecda126e6cdec556dfcd8f343b255410a9144c76ecda126e6cdec556dfcd8f343b2
linuxlinux>= f2d38e77aa5f3effc143e7dd24da8acf02925958 < 5f352a56f0e607e6ff539cbf12156bfd8af232be5f352a56f0e607e6ff539cbf12156bfd8af232be
linuxlinux_kernel< 4.14.3164.14.316
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.15 < 4.19.2844.19.284
linuxlinux_kernel>= 4.20 < 5.4.2445.4.244

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.