In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcisync: hold conn in hciconnectacl/lesync() callbacks
There is theoretical UAF if the conn is freed while the hci_sync task is running.
Hold refcount to avoid that.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98084.json"