PT-2025-8066 · Linux+2 · Linux Kernel+2
Luiz Augusto Von Dentz
+1
·
Published
2022-01-01
·
Updated
2026-05-26
·
CVE-2022-49138
CVSS v3.1
5.7
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory corruption issue exists due to the registration of devices multiple times when multiple connection complete events are received for the same handle. To address this, the code now ignores consequent events for a single connection. The introduction of HCI CONN HANDLE UNSET helps identify new connections, and checks for HCI CONN HANDLE MAX prevent the use of invalid handles.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel
Suse