Code execution via L2CAP channel use-after-free
Published Dec 9, 2025 · Updated Aug 5, 2026
Use-after-free in Linux kernel L2CAP allows physically proximate attackers to execute code through crafted Bluetooth disconnect traffic. The l2cap_disconnect_req and l2cap_disconnect_rsp handlers can acquire a reference after the channel count reaches zero, leaving teardown code to access a freed channel. An unauthenticated, unpaired device within Bluetooth range can disclose kernel heap data, corrupt kernel state, hijack control flow, or panic the host when Bluetooth is enabled.
Summary
What happened
Use-after-free in Linux kernel L2CAP allows physically proximate attackers to execute code through crafted Bluetooth disconnect traffic. The l2cap_disconnect_req and l2cap_disconnect_rsp handlers can acquire a reference after the channel count reaches zero, leaving teardown code to access a freed channel. An unauthenticated, unpaired device within Bluetooth range can disclose kernel heap data, corrupt kernel state, hijack control flow, or panic the host when Bluetooth is enabled.
The record
- CVE
- CVE-2023-53827
- Published
- Dec 9, 2025
- Updated
- Aug 5, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1210
- Attack vector
- adjacent
- Privileges
- unauthenticated
Timeline
How it unfolded
- Dec 9, 2025CVE publishedPublication date reported by the CVE source.
- Aug 5, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=3.5
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <1351551aa9058e07a20a27a158270cf84fcde621
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <348d446762e7c70778df8bafbdf3fa0df2123f58
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <a2a9339e1c9deb7e1e079e12e27a0265aea8421a
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <ac6725a634f7e8c0330610a8527f20c730b61115
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <c02421992505c95c7f3c9ad59ee35e22eac60988
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <d82a439c3cfdb28aa7e82e2e849c5c4dd9fca284
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <d9ba36c22a7bb09d6bac4cc2f243eff05da53f43
- Affected versionversion=61d6ef3e3408cdf7e622646fb90a9f7f9560b943 <f2d38e77aa5f3effc143e7dd24da8acf02925958
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo