CVE-2023-40283: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only; version 22.04 only
  • Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
  • Linux Linux Kernel: from 3.5, before 4.14.322 (fixed in 4.14.322); from 4.15, before 4.19.291 (fixed in 4.19.291); from 4.20, before 5.4.253 (fixed in 5.4.253); from 5.5, before 5.10.190 (fixed in 5.10.190); from 5.11, before 5.15.126 (fixed in 5.15.126); from 5.16, before 6.1.45 (fixed in 6.1.45); …

Published 2023-08-14. Last modified 2026-06-17.