{"id":"DEBIAN-CVE-2023-54038","details":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_conn: return ERR_PTR instead of NULL when there is no link  hci_connect_sco currently returns NULL when there is no link (i.e. when hci_conn_link() returns NULL).  sco_connect() expects an ERR_PTR in case of any error (see line 266 in sco.c). Thus, hcon set as NULL passes through to sco_conn_add(), which tries to get hcon-\u003ehdev, resulting in dereferencing a NULL pointer as reported by syzkaller.  The same issue exists for iso_connect_cis() calling hci_connect_cis().  Thus, make hci_connect_sco() and hci_connect_cis() return ERR_PTR instead of NULL.","modified":"2026-09-15T08:47:37.932311932Z","published":"2025-12-24T11:15:56.793Z","upstream":["CVE-2023-54038"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54038"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54038.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54038.json"}}],"schema_version":"1.9.0"}