cbcvebase.
CVE-2022-3640
published 2022-10-21

CVE-2022-3640: A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of…

high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211944.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.0.8-1 (bookworm)linux 6.0.8-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxkernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 4.15.0-206.2174.15.0-206.217
linuxlinux_kernel>= 0 < 5.4.0-139.1565.4.0-139.156
linuxlinux_kernel>= 0 < 5.15.0-60.665.15.0-60.66
linuxlinux_kernel>= 0 < 4.4.0-270.3044.4.0-270.304
linuxlinux_kernel>= 4.14.291 < 4.14.2994.14.299
linuxlinux_kernel>= 4.19.255 < 4.19.2654.19.265
linuxlinux_kernel>= 4.9.326 < 4.9.3334.9.333
linuxlinux_kernel>= 5.10.135 < 5.10.1545.10.154
linuxlinux_kernel>= 5.15.59 < 5.15.795.15.79
linuxlinux_kernel>= 5.18.16 < 6.0.86.0.8
linuxlinux_kernel>= 5.4.209 < 5.4.2245.4.224

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH