{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/linux-kernel--6.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.8,"id":"CVE-2023-2002"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Linux Kernel (\u003c 6.4)"],"_cs_severities":["low"],"_cs_tags":["linux","bluetooth","privilege-escalation","kernel"],"_cs_type":"advisory","_cs_vendors":["Linux"],"content_html":"\u003cp\u003eCVE-2023-2002 is a security vulnerability residing in the Linux kernel's Bluetooth subsystem, specifically within the handling of HCI socket IOCTL system calls. The vulnerability arises from insufficient permission checks when marking an HCI socket as trusted. The kernel currently verifies if the process triggering the IOCTL possesses the CAP_NET_ADMIN capability, but it fails to verify if the process that originally opened the socket also holds this permission.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by creating an HCI socket and then executing a setuid binary that performs IOCTL operations on its stdin, stdout, or stderr (e.g., sudo, su, or pkexec). These IOCTL calls trigger the kernel to mark the inherited socket as trusted. Once the HCI_SOCK_TRUSTED flag is set, it is never cleared, allowing an unprivileged user to interact with the Bluetooth management channel to send commands, pair malicious devices, or intercept sensitive data, regardless of the Bluetooth service's current power state. This vulnerability impacts Linux kernel versions prior to 6.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates a raw HCI socket using \u003ccode\u003esocket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI)\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker forks a child process to execute a setuid binary (e.g., \u003ccode\u003e/usr/bin/sudo\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker uses \u003ccode\u003edup2()\u003c/code\u003e to redirect the previously created HCI socket file descriptor to the standard I/O (stderr) of the target setuid binary.\u003c/li\u003e\n\u003cli\u003eThe setuid binary executes and performs an \u003ccode\u003eioctl\u003c/code\u003e system call to check TTY parameters on its stderr.\u003c/li\u003e\n\u003cli\u003eThe kernel \u003ccode\u003ehci_sock_ioctl\u003c/code\u003e function is triggered by the setuid process; it checks for \u003ccode\u003eCAP_NET_ADMIN\u003c/code\u003e and, finding it present in the privileged process, marks the socket with \u003ccode\u003eHCI_SOCK_TRUSTED\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe setuid process exits; the attacker retains the file descriptor for the now-trusted HCI socket.\u003c/li\u003e\n\u003cli\u003eAttacker binds the trusted socket to the management channel using \u003ccode\u003ebind()\u003c/code\u003e with \u003ccode\u003eHCI_CHANNEL_CONTROL\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker sends unauthorized Bluetooth management commands (e.g., device pairing, disabling security) to the controller.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unprivileged local user to bypass security controls in the Bluetooth subsystem. Impact includes unauthorized device pairing, exfiltration of OOB (Out-of-Band) sensitive data, and the ability to control Bluetooth controller states even if the Bluetooth service is supposedly disabled. This affects any Linux distribution running a vulnerable kernel where common setuid programs perform standard IOCTL operations on inherited file descriptors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch systems to a Linux kernel version 6.4 or later, which includes the fix replacing \u003ccode\u003ecapable()\u003c/code\u003e with \u003ccode\u003esk_capable()\u003c/code\u003e to validate the original socket opener.\u003c/li\u003e\n\u003cli\u003eIf Bluetooth is not required, use \u003ccode\u003erfkill\u003c/code\u003e to block Bluetooth devices at the hardware/kernel level as a mitigating control.\u003c/li\u003e\n\u003cli\u003eAudit environments for the presence of setuid binaries identified as triggering IOCTL calls (e.g., \u003ccode\u003esudo\u003c/code\u003e, \u003ccode\u003esu\u003c/code\u003e, \u003ccode\u003epkexec\u003c/code\u003e, \u003ccode\u003epasswd\u003c/code\u003e) to assess the attack surface.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-05T16:43:53Z","date_published":"2026-10-05T16:43:53Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2023-2002/","summary":"A vulnerability in the Linux kernel Bluetooth subsystem allows unprivileged users to gain 'trusted' status for HCI sockets by exploiting IOCTL permission check flaws, enabling unauthorized management commands.","title":"Privilege Escalation in Linux Kernel Bluetooth Subsystem via CVE-2023-2002","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2023-2002/"}],"language":"en","title":"CraftedSignal Threat Feed - Linux Kernel (\u003c 6.4)","version":"https://jsonfeed.org/version/1.1"}