CVE-2023-53017

medium

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix memory leak in hci_update_adv_data() When hci_cmd_sync_queue() failed in hci_update_adv_data(), inst_ptr is not freed, which will cause memory leak, convert to use ERR_PTR/PTR_ERR to pass the instance to callback so no memory needs to be allocated.

References

https://git.kernel.org/stable/c/8ac6043bd3e5b58d30f50737aedc2e58e8087ad5

https://git.kernel.org/stable/c/1ed8b37cbaf14574c779064ef1372af62e8ba6aa

Details

Source: Mitre, NVD

Published: 2025-03-27

Updated: 2025-04-15

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00018