CVE-2023-53520 — Race Condition in Linux
Severity
4.7MEDIUMNVD
EPSS
0.0%
top 97.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateApr 17
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Fix hci_suspend_sync crash
If hci_unregister_dev() frees the hci_dev object but hci_suspend_notifier
may still be accessing it, it can cause the program to crash.
Here's the call trace:
[102152.653246] Call Trace:
[102152.653254] hci_suspend_sync+0x109/0x301 [bluetooth]
[102152.653259] hci_suspend_dev+0x78/0xcd [bluetooth]
[102152.653263] hci_suspend_notifier+0x42/0x7a [bluetooth]
[102152.653268] notifier_call_chain…
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6
Affected Packages11 packages
▶CVEListV5linux/linux9952d90ea2885d7cbf80cd233f694f09a9c0eaec — e1fa25a91091bbed691ba2996a6cee809e3309a2+4
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-fxhr-ffpx-g953: In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Fix hci_suspend_sync crash
If hci_unregister_dev() frees the hci_dev↗2025-10-01
OSV▶
CVE-2023-53520: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix hci_suspend_sync crash If hci_unregister_dev() frees the hci_dev ob↗2025-10-01