cbcvebase.
CVE-2023-54038
published 2025-12-24

CVE-2023-54038: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: return ERR_PTR instead of NULL when there is no link hci_connect_sco…

PriorityP418medium5.5
EPSS
0.16%
5.8th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: return ERR_PTR instead of NULL when there is no link hci_connect_sco currently returns NULL when there is no link (i.e. when hci_conn_link() returns NULL). sco_connect() expects an ERR_PTR in case of any error (see line 266 in sco.c). Thus, hcon set as NULL passes through to sco_conn_add(), which tries to get hcon->hdev, resulting in dereferencing a NULL pointer as reported by syzkaller. The same issue exists for iso_connect_cis() calling hci_connect_cis(). Thus, make hci_connect_sco() and hci_connect_cis() return ERR_PTR instead of NULL.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.4.11-1 (forky)linux 6.4.11-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 06149746e7203d5ffe2d6faf9799ee36203aa8b8 < 357ab53c83a5322437fa434e9a9e3e0bafe6b383357ab53c83a5322437fa434e9a9e3e0bafe6b383
linuxlinux>= 06149746e7203d5ffe2d6faf9799ee36203aa8b8 < b4066eb04bb67e7ff66e5aaab0db4a753f37eaadb4066eb04bb67e7ff66e5aaab0db4a753f37eaad
linuxlinux>= 6.3.8 < 6.46.4
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 6.4.0 < 6.4.76.4.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.