CVE-2022-45934Integer Overflow or Wraparound in Kernel

Severity
7.8HIGHNVD
OSV8.8OSV6.7OSV6.6OSV6.5OSV6.4OSV5.5OSV4.3
EPSS
0.4%
top 38.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27
Latest updateMar 3

Description

An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages11 packages

NVDlinux/linux_kernel2.6.324.9.337+6
Debianlinux/linux_kernel< 5.10.162-1+3
Ubuntulinux/linux_kernel< 4.15.0-202.213+3
debiandebian/linux< linux 6.1.4-1 (bookworm)

Also affects: Debian Linux 11.0, Fedora 37

Patches

🔴Vulnerability Details

23
OSV
linux-bluefield vulnerabilities2023-03-03
OSV
linux-oem-6.0 vulnerabilities2023-03-03
OSV
linux-hwe-5.19 vulnerabilities2023-02-16
OSV
linux-gke-5.15 vulnerabilities2023-02-15
OSV
linux-gke vulnerabilities2023-02-15

📋Vendor Advisories

25
Ubuntu
Linux kernel (BlueField) vulnerabilities2023-03-03
Ubuntu
Linux kernel (OEM) vulnerabilities2023-03-03
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-459342023-03-02
Ubuntu
Linux kernel (HWE) vulnerabilities2023-02-16
Ubuntu
Linux kernel (GKE) vulnerabilities2023-02-15