PT-2025-8039 · Linux+5 · Linux Kernel+5

Sönke Huster

·

Published

2022-03-18

·

Updated

2025-09-29

·

CVE-2022-49111

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17.0-rc5
Description A use-after-free issue has been identified in the Linux kernel's Bluetooth functionality, specifically in the hci send acl function. This issue arises when the HCI EV DISCONN PHY LINK COMPLETE event is received, which calls hci conn del without checking if conn->type is AMP LINK, leading to improper cleanup of upper layers. The estimated number of potentially affected devices worldwide is not specified. There is no information available about real-world incidents where this issue was exploited.
Recommendations For Linux kernel versions prior to 5.17.0-rc5, update to a version that includes the fix for the use-after-free issue in the hci send acl function. As a temporary workaround, consider disabling the Bluetooth functionality until a patch is available. Restrict access to the vulnerable hci send acl function to minimize the risk of exploitation. Avoid using the hci send acl function in the affected API endpoint until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:10669
ALSA-2025:10670
ALSA-2025_10669
ALSA-2025_10670
ALSA-2025_16880
BDU:2025-10262
CESA-2025_10669
CESA-2025_10670
CVE-2022-49111
INFSA-2025_10669
INFSA-2025_10670
OESA-2025-1513
OPENSUSE-SU-2025_01633-1
OPENSUSE-SU-2025_1263-1
RHSA-2023:2458
RHSA-2023_2458
RHSA-2025:10005
RHSA-2025:10174
RHSA-2025:10179
RHSA-2025:10193
RHSA-2025:10211
RHSA-2025:10669
RHSA-2025:10670
RHSA-2025:10673
RHSA-2025_10669
RHSA-2025_10670
SUSE-SU-2025:01600-1
SUSE-SU-2025:01633-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1574-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_01633-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Suse