CVE-2022-49116
published 2025-02-26CVE-2022-49116: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: use memset avoid memory leaks Use memset to initialize structs to prevent memory…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: use memset avoid memory leaks
Use memset to initialize structs to prevent memory leaks
in l2cap_ecred_connect
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= da49b602f7f75ccc91386e1274b3ef71676cd092 < 9567d54e70ff58c2695c2cc2e53c86c67551d3e6 | 9567d54e70ff58c2695c2cc2e53c86c67551d3e6 |
| linux | linux | >= da49b602f7f75ccc91386e1274b3ef71676cd092 < 42b6a39f439b6f37cc2024d91ce547d83290ff78 | 42b6a39f439b6f37cc2024d91ce547d83290ff78 |
| linux | linux | >= da49b602f7f75ccc91386e1274b3ef71676cd092 < e9e55acee9b7a737ec7f5161b94a78932a5514c8 | e9e55acee9b7a737ec7f5161b94a78932a5514c8 |
| linux | linux | >= da49b602f7f75ccc91386e1274b3ef71676cd092 < d588c183a971b85c775ad66da563ee6e8bc8158f | d588c183a971b85c775ad66da563ee6e8bc8158f |
| linux | linux | >= da49b602f7f75ccc91386e1274b3ef71676cd092 < d3715b2333e9a21692ba16ef8645eda584a9515d | d3715b2333e9a21692ba16ef8645eda584a9515d |
| linux | linux_kernel | < 5.10.111 | 5.10.111 |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 5.11 < 5.15.34 | 5.15.34 |
| linux | linux_kernel | >= 5.16 < 5.16.20 | 5.16.20 |
| linux | linux_kernel | >= 5.17 < 5.17.3 | 5.17.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwpr-f242-c84q: In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: use memset avoid memory leaks
Use memset to initialize structs to pre
ghsa_unreviewed·2025-03-14
CVE-2022-49116 [MEDIUM] CWE-401 GHSA-fwpr-f242-c84q: In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: use memset avoid memory leaks
Use memset to initialize structs to pre
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: use memset avoid memory leaks
Use memset to initialize structs to prevent memory leaks
in l2cap_ecred_connect
OSV
CVE-2022-49116: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: use memset avoid memory leaks Use memset to initialize structs to preve
osv·2025-02-26·CVSS 5.5
CVE-2022-49116 [MEDIUM] CVE-2022-49116: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: use memset avoid memory leaks Use memset to initialize structs to preve
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: use memset avoid memory leaks Use memset to initialize structs to prevent memory leaks in l2cap_ecred_connect
Red Hat
kernel: Bluetooth: use memset avoid memory leaks
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49116 [MEDIUM] CWE-908 kernel: Bluetooth: use memset avoid memory leaks
kernel: Bluetooth: use memset avoid memory leaks
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: use memset avoid memory leaks
Use memset to initialize structs to prevent memory leaks
in l2cap_ecred_connect
Statement: The bug is that if L2CAP being used during Bluetooth connection, then data leak could happen. Means that some of the data area not initialized by zeros, so random data could potentially leak as result of l2cap_ecred_connect function usage. The security impact is limited, because this data structure being initialized with some actual data and cases when actually some random bytes leakage could happen limited.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Securit
Debian
CVE-2022-49116: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...
vendor_debian·2022·CVSS 5.5
CVE-2022-49116 [MEDIUM] CVE-2022-49116: linux - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ...
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: use memset avoid memory leaks Use memset to initialize structs to prevent memory leaks in l2cap_ecred_connect
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/42b6a39f439b6f37cc2024d91ce547d83290ff78https://git.kernel.org/stable/c/9567d54e70ff58c2695c2cc2e53c86c67551d3e6https://git.kernel.org/stable/c/d3715b2333e9a21692ba16ef8645eda584a9515dhttps://git.kernel.org/stable/c/d588c183a971b85c775ad66da563ee6e8bc8158fhttps://git.kernel.org/stable/c/e9e55acee9b7a737ec7f5161b94a78932a5514c8
2025-02-26
Published