In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
There is theoretical UAF if the conn is freed while the hci_sync task is running.
Hold refcount to avoid that.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98084.json"