CVE-2022-49136

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 26, 2025
Updated: Feb 27, 2025
CWE ID 416

Summary

CVE-2022-49136 is a vulnerability affecting the Linux kernel's Bluetooth subsystem. The issue involves a problem with command queuing in the hci_sync function. When the HCI_UNREGISTER flag is set, indicating that hci_unregister_dev has been called, hci_cmd_sync_queue should return an error. However, if an error is not returned, the system may experience a use-after-free (UAF) condition upon timeout, as the associated hdev will have been freed. This vulnerability could potentially lead to unintended system behavior or even exploitation. The Linux kernel developers have addressed this issue through appropriate fixes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share