important · Bluetooth
A local BlueZ media client can trigger a use-after-free in root bluetoothd during LE Audio teardown.
Affects
BlueZ, the Linux Bluetooth userspace stack and system bluetoothd daemon, when LE Audio uses linked media transports.
A replaced owner can retain a disconnect watch and transport pointer after the transport is freed, causing its later disconnect callback to dereference freed memory.
Detail and 4 sources
We do not know whether a client can deterministically reuse the allocation and influence callback-reachable data.
Chain to watch
Create competing ownership around linked LE Audio transports→↓Free a transport while the old owner retains its pointer→↓Disconnect the old owner and dereference freed memory→↓Allocator control beyond a crash has not been demonstrated.
Unverified chainReproduce under ASan with two competing owners, groom the freed allocation, and test influence over callback fields or control flow.
Sources
Researcha03665b6dd20e3b62501867c0dcc7ca6f74d7ae9 - pub/scm/bluetooth/bluez - Git at GoogleCode / PoCbluez/src/bluetooth.conf at master · bluez/bluez · GitHubPatchhttps://github.com/bluez/bluez/commit/a03665b6dd20e3b62501867c0dcc7ca6f74d7ae9.patchSecondarytransport: Fix use-after-free when replacing a linked transport's owner · bluez/bluez@a03665b