cbcvebase.
CVE-2023-53386
published 2025-09-18

CVE-2023-53386: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix potential use-after-free when clear keys Similar to commit c5d2b6fa26b5…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.7th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix potential use-after-free when clear keys Similar to commit c5d2b6fa26b5 ("Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk"). We can not access k after kfree_rcu() call.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= d7d41682efc25d58b5bd8b80e85e3c9ce586635c < e87da6a0ac6e631454e7da53a76aa9fe44aaa5dde87da6a0ac6e631454e7da53a76aa9fe44aaa5dd
linuxlinux>= d7d41682efc25d58b5bd8b80e85e3c9ce586635c < 942d8cefb022f384d5424f8b90c7878f3f93726f942d8cefb022f384d5424f8b90c7878f3f93726f
linuxlinux>= d7d41682efc25d58b5bd8b80e85e3c9ce586635c < 94617b736c25091b60e514e2e7aeafcbbee6b70094617b736c25091b60e514e2e7aeafcbbee6b700
linuxlinux>= d7d41682efc25d58b5bd8b80e85e3c9ce586635c < da19f35868dfbecfff4f81166c054d2656cb1be4da19f35868dfbecfff4f81166c054d2656cb1be4
linuxlinux>= d7d41682efc25d58b5bd8b80e85e3c9ce586635c < 35cc42f04bc49f0656f6840cb7451b3df604964935cc42f04bc49f0656f6840cb7451b3df6049649
linuxlinux>= d7d41682efc25d58b5bd8b80e85e3c9ce586635c < 3673952cf0c6cf81b06c66a0b788abeeb02ff3ae3673952cf0c6cf81b06c66a0b788abeeb02ff3ae
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 5.11 < 5.15.1325.15.132
linuxlinux_kernel>= 5.16 < 6.1.536.1.53
linuxlinux_kernel>= 5.7 < 5.10.1955.10.195
linuxlinux_kernel>= 6.2 < 6.4.166.4.16
linuxlinux_kernel>= 6.5 < 6.5.36.5.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.