Red Hat released kernel and real-time kernel updates for CVE-2023-40283, a CVSS 7.8 use-after-free flaw in the Linux Bluetooth L2CAP socket-release routine, l2cap_sock_release. Improper handling of child sockets can allow a local low-privileged user to trigger the vulnerability, potentially compromising confidentiality, integrity, and availability. The upstream fix is commit 1728137b33c00d5a2b5110ed7aafb42e7c32e4a1, included in Linux kernel 6.4.10; Red Hat reported no qualifying mitigation beyond updating affected systems.
Affected Red Hat Enterprise Linux 8.4 support channels received kernel 4.18.0-305.130.1.el8_4 under RHSA-2024:2582, while relevant RHEL 8.4 real-time deployments received kernel-rt 4.18.0-305.130.1.rt7.206.el8_4 through RHSA-2024:2585. RHSA-2024:10772 also includes the remediation in kernel 5.14.0-284.95.1.el9_2 for RHEL 9.2 update channels. Administrators should install the applicable updated kernel packages and reboot to activate the fixes.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:0881 for RHEL 8 kernel-rt and RHSA-2024:0897 for the RHEL 8 kernel, remediating CVE-2023-40283.
Rohit Keshri disclosed CVE-2023-40283, a use-after-free in the Linux kernel's Bluetooth L2CAP l2cap_sock_release routine caused by mishandling socket children.
Red Hat issued RHSA-2024:2582 and RHSA-2024:2585 for supported RHEL 8.4 channels, fixing CVE-2023-40283 in kernel version 4.18.0-305.130.1.el8_4 and kernel-rt version 4.18.0-305.130.1.rt7.206.el8_4.
Red Hat issued RHSA-2024:1268 and RHSA-2024:1269 to fix CVE-2023-40283 for RHEL 8.2 Advanced Update Support, Telecommunications Update Service, and SAP update-service kernel channels.
The upstream Linux kernel project fixed the Bluetooth L2CAP use-after-free in commit 1728137b33c00d5a2b5110ed7aafb42e7c32e4a1; the fix is included in Linux kernel 6.4.10.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.