btsockrecvmsg in net/bluetooth/afbluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a btsock_ioctl race condition.
{ "urgency": "not yet assigned" }