Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Peng Hui

#48156of 53,632
5.3Total CVSS
Vulnerabilities · 1
PT-2023-2056
5.3
2023-03-20
Linux · Linux Kernel · CVE-2023-28866
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions through 6.2.8 **Description** The issue is related to out-of-bounds access in the Linux kernel, specifically in the net/bluetooth/hci sync.c file. This is due to the amp init1[] and amp init2[] arrays not having an intentionally invalid element as supposed. The vulnerability can be exploited by a remote attacker to disclose protected information. **Recommendations** For Linux kernel versions through 6.2.8, update to a version later than 6.2.8 to resolve the issue. As a temporary workaround, consider restricting access to the net/bluetooth/hci sync.c module to minimize the risk of exploitation.