
From a tiny race condition in Linux Bluetooth SCO to a full kernel LPE. The Secunnix team dissected the vulnerable path, engineered a heap spray + SMEP bypass, and turned a subtle UAF into reliable uid=0 execution all demonstrated on real QEMU/KVM runs. https://scnx.com/blog/cve-2024-27398-exploiting-a-linux-bluetooth-sco-use-after-free-with-smep-bypass
Post summary
The text announces a detailed PoC for CVE-2024-27398, describing exploitation of a Linux Bluetooth SCO UAF vulnerability with heap spray and SMEP bypass techniques, resulting in kernel LPE, and links to a blog post with full technical details.



