CVE-2023-54197
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54197 is a Linux kernel vulnerability in the Bluetooth btsdio driver, introduced by a faulty patch that was subsequently reverted. Specifically, commit 1e9ac114c442 ("Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work") introduced a possible null-pointer dereference (null-ptr-deref) problem in the btsdio_remove function. The CVE was published on December 30, 2025, and affects multiple stable Linux kernel branches prior to the revert commits. Feedly estimates the severity as HIGH, with an EPSS score of approximately 0.033% (Feedly).

Technical details

The root cause is a null-pointer dereference (CWE-476) introduced by commit 1e9ac114c4428fdb7ff4635b45d4f46017e8916f, which attempted to fix a use-after-free bug in the btsdio_remove function of the Linux kernel's Bluetooth SDIO driver. The original use-after-free issue (triggered by a race condition during device removal) was subsequently addressed correctly by commit 73f7b171b7c0 ("Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition"). The faulty intermediate commit was reverted across multiple stable kernel branches (4.14.x, 4.19.x, 5.4.x, 5.10.x, 5.15.x, 6.1.x, 6.2.x, 6.3.x, and 6.4) via corresponding revert commits (Feedly, EUVD).

Impact

Exploitation of the null-pointer dereference could cause a kernel panic or system crash, impacting availability of the affected Linux system. In some kernel configurations, null-pointer dereferences may be leveraged for local privilege escalation, though the practical exploitability for privilege escalation depends heavily on kernel hardening settings (e.g., mmap_min_addr). The vulnerability is confined to systems with Bluetooth SDIO hardware and the btsdio kernel module loaded (Feedly).

Mitigation and workarounds

The fix is to update to a Linux kernel version that includes the revert of commit 1e9ac114c442. Patched stable versions include 4.14.315, 4.19.283, 5.4.243, 5.10.180, 5.15.111, 6.1.28, 6.2.15, 6.3.2, and 6.4+. As a workaround on systems that do not require Bluetooth SDIO functionality, unloading or blacklisting the btsdio kernel module will prevent exposure. Administrators should apply the relevant stable kernel update for their distribution as the primary remediation (Feedly, EUVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management