CVE-2023-53297 (GCVE-0-2023-53297)

Vulnerability from cvelistv5 – Published: 2025-09-16 08:11 – Updated: 2026-08-05 09:13
VLAI
Title
Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp conn->chan_lock isn't acquired before l2cap_get_chan_by_scid, if l2cap_get_chan_by_scid returns NULL, then 'bad unlock balance' is triggered.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-01-14 18:12 UTC
Impacted products
Vendor Product Version
Linux Linux Affected: f2d38e77aa5f3effc143e7dd24da8acf02925958 , < 5f352a56f0e607e6ff539cbf12156bfd8af232be (git)
Affected: 1351551aa9058e07a20a27a158270cf84fcde621 , < 6a27762340ad08643de3bc17fe1646ea489ca2e2 (git)
Affected: c02421992505c95c7f3c9ad59ee35e22eac60988 , < 2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d (git)
Affected: d9ba36c22a7bb09d6bac4cc2f243eff05da53f43 , < 55410a9144c76ecda126e6cdec556dfcd8f343b2 (git)
Affected: ac6725a634f7e8c0330610a8527f20c730b61115 , < 116b9c002c894097adc2b8684db2d1da4229ed46 (git)
Affected: 348d446762e7c70778df8bafbdf3fa0df2123f58 , < fd269a0435f8e9943b7a57c5a59688848d42d449 (git)
Affected: a2a9339e1c9deb7e1e079e12e27a0265aea8421a , < 5134556c9be582793f30695c09d18a26fe1ff2d7 (git)
Affected: a2a9339e1c9deb7e1e079e12e27a0265aea8421a , < 25e97f7b1866e6b8503be349eeea44bb52d661ce (git)
Affected: d82a439c3cfdb28aa7e82e2e849c5c4dd9fca284 (git)
Affected: 4.14.313 , < 4.14.316 (semver)
Affected: 4.19.281 , < 4.19.284 (semver)
Affected: 5.4.241 , < 5.4.244 (semver)
Affected: 5.10.178 , < 5.10.181 (semver)
Affected: 5.15.108 , < 5.15.113 (semver)
Affected: 6.1.25 , < 6.1.30 (semver)
Affected: 6.2.12 , < 6.3 (semver)
Create a notification for this product.
Linux Linux Affected: 6.3
Unaffected: 0 , < 6.3 (semver)
Unaffected: 4.14.316 , ≤ 4.14.* (semver)
Unaffected: 4.19.284 , ≤ 4.19.* (semver)
Unaffected: 5.4.244 , ≤ 5.4.* (semver)
Unaffected: 5.10.181 , ≤ 5.10.* (semver)
Unaffected: 5.15.113 , ≤ 5.15.* (semver)
Unaffected: 6.1.30 , ≤ 6.1.* (semver)
Unaffected: 6.3.4 , ≤ 6.3.* (semver)
Unaffected: 6.4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 5.5,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2023-53297",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-01-14T18:12:33.884627Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-01-14T18:12:56.873Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/l2cap_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "5f352a56f0e607e6ff539cbf12156bfd8af232be",
              "status": "affected",
              "version": "f2d38e77aa5f3effc143e7dd24da8acf02925958",
              "versionType": "git"
            },
            {
              "lessThan": "6a27762340ad08643de3bc17fe1646ea489ca2e2",
              "status": "affected",
              "version": "1351551aa9058e07a20a27a158270cf84fcde621",
              "versionType": "git"
            },
            {
              "lessThan": "2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d",
              "status": "affected",
              "version": "c02421992505c95c7f3c9ad59ee35e22eac60988",
              "versionType": "git"
            },
            {
              "lessThan": "55410a9144c76ecda126e6cdec556dfcd8f343b2",
              "status": "affected",
              "version": "d9ba36c22a7bb09d6bac4cc2f243eff05da53f43",
              "versionType": "git"
            },
            {
              "lessThan": "116b9c002c894097adc2b8684db2d1da4229ed46",
              "status": "affected",
              "version": "ac6725a634f7e8c0330610a8527f20c730b61115",
              "versionType": "git"
            },
            {
              "lessThan": "fd269a0435f8e9943b7a57c5a59688848d42d449",
              "status": "affected",
              "version": "348d446762e7c70778df8bafbdf3fa0df2123f58",
              "versionType": "git"
            },
            {
              "lessThan": "5134556c9be582793f30695c09d18a26fe1ff2d7",
              "status": "affected",
              "version": "a2a9339e1c9deb7e1e079e12e27a0265aea8421a",
              "versionType": "git"
            },
            {
              "lessThan": "25e97f7b1866e6b8503be349eeea44bb52d661ce",
              "status": "affected",
              "version": "a2a9339e1c9deb7e1e079e12e27a0265aea8421a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d82a439c3cfdb28aa7e82e2e849c5c4dd9fca284",
              "versionType": "git"
            },
            {
              "lessThan": "4.14.316",
              "status": "affected",
              "version": "4.14.313",
              "versionType": "semver"
            },
            {
              "lessThan": "4.19.284",
              "status": "affected",
              "version": "4.19.281",
              "versionType": "semver"
            },
            {
              "lessThan": "5.4.244",
              "status": "affected",
              "version": "5.4.241",
              "versionType": "semver"
            },
            {
              "lessThan": "5.10.181",
              "status": "affected",
              "version": "5.10.178",
              "versionType": "semver"
            },
            {
              "lessThan": "5.15.113",
              "status": "affected",
              "version": "5.15.108",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1.30",
              "status": "affected",
              "version": "6.1.25",
              "versionType": "semver"
            },
            {
              "lessThan": "6.3",
              "status": "affected",
              "version": "6.2.12",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/l2cap_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "lessThan": "6.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.14.*",
              "status": "unaffected",
              "version": "4.14.316",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.284",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.244",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.181",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.30",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.3.*",
              "status": "unaffected",
              "version": "6.3.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.14.316",
                  "versionStartIncluding": "4.14.313",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.284",
                  "versionStartIncluding": "4.19.281",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.244",
                  "versionStartIncluding": "5.4.241",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.181",
                  "versionStartIncluding": "5.10.178",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.113",
                  "versionStartIncluding": "5.15.108",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.30",
                  "versionStartIncluding": "6.1.25",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.3.4",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.4",
                  "versionStartIncluding": "6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.2.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix \"bad unlock balance\" in l2cap_disconnect_rsp\n\nconn-\u003echan_lock isn\u0027t acquired before l2cap_get_chan_by_scid,\nif l2cap_get_chan_by_scid returns NULL, then \u0027bad unlock balance\u0027\nis triggered."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - The bug is reached only by processing an L2CAP Disconnect Response on the BR/EDR or LE signaling CID (hci_rx_work \u2192 l2cap_recv_acldata \u2192 l2cap_recv_frame \u2192 l2cap_disconnect_rsp), which requires a Bluetooth peer within radio range; kernel guidance maps Bluetooth to Adjacent.\nAC:L - The attacker reliably triggers the bad unlock by sending DISCONN_RSP with a nonexistent SCID, and can also drive concurrent chan_lock holders (channel timers, connect/disconnect churn) so the premature unlock races list walks; both sides are attacker-influenced with no uncontrollable condition.\nPR:N - l2cap_recv_frame dispatches CID 0x0001/0x0005 to the signaling handlers with no pairing, encryption, or security-level check, so an unauthenticated in-range device can send the triggering PDU on an established ACL/LE link.\nUI:N - No victim action is required; once the host is connectable/advertising with Bluetooth enabled (default on phones, cars, and laptops), the crafted PDU is processed automatically by hci_rx_work.\nS:U - Impact stays inside the host kernel Bluetooth/L2CAP authority; this is standard kernel memory-safety compromise, not a VM, IOMMU, or sandbox boundary crossing.\nC:H - Unlocking conn-\u003echan_lock while another context (e.g. l2cap_chan_timeout) holds it exposes conn-\u003echan_l to unsynchronized list manipulation and use-after-free of struct l2cap_chan, which per guidance enables heap reuse and arbitrary kernel read primitives.\nI:H - The same premature unlock races l2cap_chan_del/list walks against concurrent channel ops, yielding use-after-free write and function-pointer hijack primitives via sprayed reclaimed channel objects.\nA:H - The defect produces a lockdep \"bad unlock balance\" WARNING (panic under panic_on_warn) and, when it unlocks under a concurrent holder, use-after-free crashes/oopses on the channel list that an adjacent peer can re-trigger at will."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:13:24.678Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5f352a56f0e607e6ff539cbf12156bfd8af232be"
        },
        {
          "url": "https://git.kernel.org/stable/c/6a27762340ad08643de3bc17fe1646ea489ca2e2"
        },
        {
          "url": "https://git.kernel.org/stable/c/2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d"
        },
        {
          "url": "https://git.kernel.org/stable/c/55410a9144c76ecda126e6cdec556dfcd8f343b2"
        },
        {
          "url": "https://git.kernel.org/stable/c/116b9c002c894097adc2b8684db2d1da4229ed46"
        },
        {
          "url": "https://git.kernel.org/stable/c/fd269a0435f8e9943b7a57c5a59688848d42d449"
        },
        {
          "url": "https://git.kernel.org/stable/c/5134556c9be582793f30695c09d18a26fe1ff2d7"
        },
        {
          "url": "https://git.kernel.org/stable/c/25e97f7b1866e6b8503be349eeea44bb52d661ce"
        }
      ],
      "title": "Bluetooth: L2CAP: fix \"bad unlock balance\" in l2cap_disconnect_rsp",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-53297",
    "datePublished": "2025-09-16T08:11:29.283Z",
    "dateReserved": "2025-09-16T08:09:37.993Z",
    "dateUpdated": "2026-08-05T09:13:24.678Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2023-53297",
      "date": "2026-10-03",
      "epss": "0.00215",
      "percentile": "0.10836"
    },
    "vulnrichment": {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 5.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-53297",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-14T18:12:33.884627Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "description": "CWE-noinfo Not enough information",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-14T18:12:29.419Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/bluetooth/l2cap_core.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "5f352a56f0e607e6ff539cbf12156bfd8af232be",
                  "status": "affected",
                  "version": "f2d38e77aa5f3effc143e7dd24da8acf02925958",
                  "versionType": "git"
                },
                {
                  "lessThan": "6a27762340ad08643de3bc17fe1646ea489ca2e2",
                  "status": "affected",
                  "version": "1351551aa9058e07a20a27a158270cf84fcde621",
                  "versionType": "git"
                },
                {
                  "lessThan": "2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d",
                  "status": "affected",
                  "version": "c02421992505c95c7f3c9ad59ee35e22eac60988",
                  "versionType": "git"
                },
                {
                  "lessThan": "55410a9144c76ecda126e6cdec556dfcd8f343b2",
                  "status": "affected",
                  "version": "d9ba36c22a7bb09d6bac4cc2f243eff05da53f43",
                  "versionType": "git"
                },
                {
                  "lessThan": "116b9c002c894097adc2b8684db2d1da4229ed46",
                  "status": "affected",
                  "version": "ac6725a634f7e8c0330610a8527f20c730b61115",
                  "versionType": "git"
                },
                {
                  "lessThan": "fd269a0435f8e9943b7a57c5a59688848d42d449",
                  "status": "affected",
                  "version": "348d446762e7c70778df8bafbdf3fa0df2123f58",
                  "versionType": "git"
                },
                {
                  "lessThan": "5134556c9be582793f30695c09d18a26fe1ff2d7",
                  "status": "affected",
                  "version": "a2a9339e1c9deb7e1e079e12e27a0265aea8421a",
                  "versionType": "git"
                },
                {
                  "lessThan": "25e97f7b1866e6b8503be349eeea44bb52d661ce",
                  "status": "affected",
                  "version": "a2a9339e1c9deb7e1e079e12e27a0265aea8421a",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "d82a439c3cfdb28aa7e82e2e849c5c4dd9fca284",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/bluetooth/l2cap_core.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.3"
                },
                {
                  "lessThan": "6.3",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.14.*",
                  "status": "unaffected",
                  "version": "4.14.316",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.19.*",
                  "status": "unaffected",
                  "version": "4.19.284",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.244",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.181",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.113",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.30",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.3.*",
                  "status": "unaffected",
                  "version": "6.3.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.4",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.14.316",
                      "versionStartIncluding": "4.14.313",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.19.284",
                      "versionStartIncluding": "4.19.281",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.244",
                      "versionStartIncluding": "5.4.241",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.181",
                      "versionStartIncluding": "5.10.178",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.113",
                      "versionStartIncluding": "5.15.108",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.30",
                      "versionStartIncluding": "6.1.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.3.4",
                      "versionStartIncluding": "6.3",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.4",
                      "versionStartIncluding": "6.3",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "6.2.12",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix \"bad unlock balance\" in l2cap_disconnect_rsp\n\nconn-\u003echan_lock isn\u0027t acquired before l2cap_get_chan_by_scid,\nif l2cap_get_chan_by_scid returns NULL, then \u0027bad unlock balance\u0027\nis triggered."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-05T10:19:18.834Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/5f352a56f0e607e6ff539cbf12156bfd8af232be"
            },
            {
              "url": "https://git.kernel.org/stable/c/6a27762340ad08643de3bc17fe1646ea489ca2e2"
            },
            {
              "url": "https://git.kernel.org/stable/c/2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d"
            },
            {
              "url": "https://git.kernel.org/stable/c/55410a9144c76ecda126e6cdec556dfcd8f343b2"
            },
            {
              "url": "https://git.kernel.org/stable/c/116b9c002c894097adc2b8684db2d1da4229ed46"
            },
            {
              "url": "https://git.kernel.org/stable/c/fd269a0435f8e9943b7a57c5a59688848d42d449"
            },
            {
              "url": "https://git.kernel.org/stable/c/5134556c9be582793f30695c09d18a26fe1ff2d7"
            },
            {
              "url": "https://git.kernel.org/stable/c/25e97f7b1866e6b8503be349eeea44bb52d661ce"
            }
          ],
          "title": "Bluetooth: L2CAP: fix \"bad unlock balance\" in l2cap_disconnect_rsp",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2023-53297",
        "datePublished": "2025-09-16T08:11:29.283Z",
        "dateReserved": "2025-09-16T08:09:37.993Z",
        "dateUpdated": "2026-01-14T18:12:56.873Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…