PT-2021-6920 · Linux+4 · Linux Kernel+4

Sönke Huster

·

Published

2021-10-20

·

Updated

2025-05-05

·

CVE-2022-26878

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16.3
Description The issue is related to a memory leak in the Linux kernel, specifically in the drivers/bluetooth/virtio bt.c file. This memory leak occurs because socket buffers have memory allocated but not freed. The exploitation of this issue can allow a remote attacker to cause a denial of service.
Recommendations For Linux kernel versions prior to 5.16.3, update to version 5.16.3 or later to resolve the memory leak issue. As a temporary workaround, consider restricting access to the vulnerable virtio bt.c driver to minimize the risk of exploitation.

Fix

Missing Release of Resource after Effective Lifetime

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1171
ALT-PU-2022-1175
ALT-PU-2022-1647
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-9066
BDU:2022-02677
CVE-2022-26878
USN-5383-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu