L2CAP Vulnerability in Linux Kernel Bluetooth Stack
CVE-2023-53297

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2025

What is CVE-2023-53297?

A vulnerability has been identified in the Linux kernel's Bluetooth subsystem concerning the L2CAP protocol. The issue arises due to an improper locking mechanism linked to the conn->chan_lock. Specifically, if the function l2cap_get_chan_by_scid returns NULL, it leads to a 'bad unlock balance' scenario. This abnormality could have implications for system stability and security, necessitating the application of relevant patches and updates to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux f2d38e77aa5f3effc143e7dd24da8acf02925958 < 5f352a56f0e607e6ff539cbf12156bfd8af232be

Linux 1351551aa9058e07a20a27a158270cf84fcde621 < 6a27762340ad08643de3bc17fe1646ea489ca2e2

Linux c02421992505c95c7f3c9ad59ee35e22eac60988 < 2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.