cbcvebase.
CVE-2022-42896
published 2022-11-23

CVE-2022-42896: There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow…

PriorityP350high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
2.01%
78.7th percentile
There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.10-1 (bookworm)linux 6.0.10-1 (bookworm)
linuxlinux_kernel< 4.9.3354.9.335
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 6.0.10-16.0.10-1
linuxlinux_kernel>= 0 < 4.15.0-202.2134.15.0-202.213
linuxlinux_kernel>= 0 < 5.4.0-137.1545.4.0-137.154
linuxlinux_kernel>= 0 < 5.15.0-58.645.15.0-58.64
linuxlinux_kernel>= 0 < 4.4.0-236.2704.4.0-236.270
linuxlinux_kernel>= 0 < 4.15.0-202.2134.15.0-202.213
linuxlinux_kernel>= 0 < 5.4.0-137.1545.4.0-137.154
linuxlinux_kernel>= 0 < 5.15.0-58.645.15.0-58.64
linuxlinux_kernel3.0.0 – 711f8c3fb3db61897080468586b970c87c61d9e4
linuxlinux_kernel>= 4.10 < 4.14.3014.14.301
linuxlinux_kernel>= 4.15 < 4.19.2684.19.268
linuxlinux_kernel>= 4.20 < 5.4.2265.4.226
linuxlinux_kernel>= 5.11 < 5.15.785.15.78
linuxlinux_kernel>= 5.16 < 6.0.86.0.8
linuxlinux_kernel>= 5.5 < 5.10.1545.10.154

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
vendor_ubuntu8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.