CVE-2022-3637
published 2022-10-21CVE-2022-3637: A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.2th percentile
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211936.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | < 5.65 | 5.65 |
| debian | bluez | — | — |
| linux | kernel | — | — |
| msrc | azl3_bluez_5.63-6_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_debian2.6LOW
vendor_msrc2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-neutron: unrestricted creation of security groups (fix for CVE-2022-3277)
vendor_redhat·2023-07-12·CVSS 6.5
CVE-2023-3637 [MEDIUM] CWE-400 openstack-neutron: unrestricted creation of security groups (fix for CVE-2022-3277)
openstack-neutron: unrestricted creation of security groups (fix for CVE-2022-3277)
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of ser
Red Hat
bluez: monitor: Fix crash when using RTT backend
vendor_redhat·2023-03-27·CVSS 2.6
CVE-2022-3637 [LOW] CWE-404 bluez: monitor: Fix crash when using RTT backend
bluez: monitor: Fix crash when using RTT backend
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211936.
A flaw was found in the Linux Kernel, affecting the jlink_init function of the monitor/jlink.c file in the BlueZ component. Manipulation leads to a denial of service.
Package: bluez (Red Hat Enterprise Linux 6) - Out of support scope
Package: bluez (Red Hat Enterprise Linux 7) - Out of support scope
Package: bluez (Red Hat Enterprise Linux 8) - Fix deferred
Package: bluez (Red Hat Enterprise Linux 9) - Fix def
Microsoft
Linux Kernel BlueZ jlink.c jlink_init denial of service
vendor_msrc·2022-10-11·CVSS 2.6
CVE-2022-3637 [LOW] CWE-404 Linux Kernel BlueZ jlink.c jlink_init denial of service
Linux Kernel BlueZ jlink.c jlink_init denial of service
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Debian
CVE-2022-3637: bluez - A vulnerability has been found in Linux Kernel and classified as problematic. Th...
vendor_debian·2022·CVSS 2.6
CVE-2022-3637 [LOW] CVE-2022-3637: bluez - A vulnerability has been found in Linux Kernel and classified as problematic. Th...
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211936.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
VulDB
Linux Kernel BlueZ monitor/jlink.c jlink_init denial of service (EUVD-2022-42997 / WID-SEC-2022-1823)
vuldb·2026-07-18·CVSS 5.5
CVE-2022-3637 [MEDIUM] Linux Kernel BlueZ monitor/jlink.c jlink_init denial of service (EUVD-2022-42997 / WID-SEC-2022-1823)
A vulnerability has been found in Linux Kernel and classified as problematic. This impacts the function jlink_init of the file monitor/jlink.c of the component BlueZ. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2022-3637. Access to the local network is required for this attack. No exploit is available.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-fm4c-gvmr-hvgr: A vulnerability has been found in Linux Kernel and classified as problematic
ghsa_unreviewed·2022-10-21
CVE-2022-3637 [MEDIUM] CWE-404 GHSA-fm4c-gvmr-hvgr: A vulnerability has been found in Linux Kernel and classified as problematic
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211936.
OSV
CVE-2022-3637: A vulnerability has been found in Linux Kernel and classified as problematic
osv·2022-10-21·CVSS 5.5
CVE-2022-3637 [MEDIUM] CVE-2022-3637: A vulnerability has been found in Linux Kernel and classified as problematic
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211936.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-21
Published