CVE-2022-49111

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 26, 2025
Updated: Feb 27, 2025
CWE ID 416

Summary

CVE-2022-49111: A vulnerability was identified and resolved in the Linux kernel's Bluetooth subsystem. The issue involved a use-after-free condition in the hci_send_acl function, which could lead to memory corruption. The bug was triggered by receiving a specific event, causing the upper layers to not be properly cleaned up. The affected memory belonged to an object allocated by task 45, and the buggy address was located within a 128-byte region of size 128. The vulnerability was detected and reported by the kernel address sanitizer (KASAN).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share