A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race condition, and lead to a UAF problem on the hdev devices. This bug has been submitted to upstream and got fixed in [1] and [2] [1] https://lore.kernel.org/all/167883542095.4543.7797236411801708072.git-patchwork-notify@kernel.org/ [2] https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=f132c2d13088
*** Bug 2185888 has been marked as a duplicate of this bug. ***