<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Linux Kernel (&lt; 6.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/linux-kernel--6.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 16:43:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/linux-kernel--6.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in Linux Kernel Bluetooth Subsystem via CVE-2023-2002</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2023-2002/</link><pubDate>Mon, 05 Oct 2026 16:43:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2023-2002/</guid><description>A vulnerability in the Linux kernel Bluetooth subsystem allows unprivileged users to gain 'trusted' status for HCI sockets by exploiting IOCTL permission check flaws, enabling unauthorized management commands.</description><content:encoded><![CDATA[<p>CVE-2023-2002 is a security vulnerability residing in the Linux kernel's Bluetooth subsystem, specifically within the handling of HCI socket IOCTL system calls. The vulnerability arises from insufficient permission checks when marking an HCI socket as trusted. The kernel currently verifies if the process triggering the IOCTL possesses the CAP_NET_ADMIN capability, but it fails to verify if the process that originally opened the socket also holds this permission.</p>
<p>An attacker can exploit this by creating an HCI socket and then executing a setuid binary that performs IOCTL operations on its stdin, stdout, or stderr (e.g., sudo, su, or pkexec). These IOCTL calls trigger the kernel to mark the inherited socket as trusted. Once the HCI_SOCK_TRUSTED flag is set, it is never cleared, allowing an unprivileged user to interact with the Bluetooth management channel to send commands, pair malicious devices, or intercept sensitive data, regardless of the Bluetooth service's current power state. This vulnerability impacts Linux kernel versions prior to 6.4.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker creates a raw HCI socket using <code>socket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI)</code>.</li>
<li>Attacker forks a child process to execute a setuid binary (e.g., <code>/usr/bin/sudo</code>).</li>
<li>Attacker uses <code>dup2()</code> to redirect the previously created HCI socket file descriptor to the standard I/O (stderr) of the target setuid binary.</li>
<li>The setuid binary executes and performs an <code>ioctl</code> system call to check TTY parameters on its stderr.</li>
<li>The kernel <code>hci_sock_ioctl</code> function is triggered by the setuid process; it checks for <code>CAP_NET_ADMIN</code> and, finding it present in the privileged process, marks the socket with <code>HCI_SOCK_TRUSTED</code>.</li>
<li>The setuid process exits; the attacker retains the file descriptor for the now-trusted HCI socket.</li>
<li>Attacker binds the trusted socket to the management channel using <code>bind()</code> with <code>HCI_CHANNEL_CONTROL</code>.</li>
<li>Attacker sends unauthorized Bluetooth management commands (e.g., device pairing, disabling security) to the controller.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unprivileged local user to bypass security controls in the Bluetooth subsystem. Impact includes unauthorized device pairing, exfiltration of OOB (Out-of-Band) sensitive data, and the ability to control Bluetooth controller states even if the Bluetooth service is supposedly disabled. This affects any Linux distribution running a vulnerable kernel where common setuid programs perform standard IOCTL operations on inherited file descriptors.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch systems to a Linux kernel version 6.4 or later, which includes the fix replacing <code>capable()</code> with <code>sk_capable()</code> to validate the original socket opener.</li>
<li>If Bluetooth is not required, use <code>rfkill</code> to block Bluetooth devices at the hardware/kernel level as a mitigating control.</li>
<li>Audit environments for the presence of setuid binaries identified as triggering IOCTL calls (e.g., <code>sudo</code>, <code>su</code>, <code>pkexec</code>, <code>passwd</code>) to assess the attack surface.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>linux</category><category>bluetooth</category><category>privilege-escalation</category><category>kernel</category></item></channel></rss>