CVE-2023-2002: Debian Linux

Medium severity, CVSS 6.8. EPSS: 1.5% chance of exploitation in the next 30 days.

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Linux Linux Kernel: before 6.4 (fixed in 6.4)

Published 2023-05-26. Last modified 2026-06-17.