CVE-2022-49136
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-49136 is a vulnerability affecting the Linux kernel's Bluetooth subsystem. The issue involves a problem with command queuing in the hci_sync function. When the HCI_UNREGISTER flag is set, indicating that hci_unregister_dev has been called, hci_cmd_sync_queue should return an error. However, if an error is not returned, the system may experience a use-after-free (UAF) condition upon timeout, as the associated hdev will have been freed. This vulnerability could potentially lead to unintended system behavior or even exploitation. The Linux kernel developers have addressed this issue through appropriate fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX