Linux Kernel Bluetooth l2cap_core.c l2cap_reassemble_sdu use after free
Published Oct 17, 2022
7.1
HIGHCVSS 3.1
EPSS 1.34%
Description
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.
Affected products
Configuration 1
- ≥ 3.6 · < 4.9.333
- ≥ 4.10 · < 4.14.299
- ≥ 4.15 · < 4.19.265
- ≥ 4.20 · < 5.4.224
- ≥ 5.5.0 · < 5.10.154
- ≥ 5.11 · < 5.15.78
- ≥ 5.16 · < 6.0.8
Configuration 2
- 10.0
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.95.1.el7
Fixed · RHSA-2023:4151
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.95.1.rt56.1241.el7
Fixed · RHSA-2023:4150
Red Hat Enterprise Linux 7
kpatch-patch
Fixed · RHSA-2023:4215
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.111.1.el7
Fixed · RHSA-2023:4020
Red Hat Enterprise Linux 7.6 Advanced Update Support
kernel-0:3.10.0-957.104.1.el7
Fixed · RHSA-2023:4021
Red Hat Enterprise Linux 7.7 Advanced Update Support
kernel-0:3.10.0-1062.72.1.el7
Fixed · RHSA-2023:3277
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
kernel-0:3.10.0-1062.72.1.el7
Fixed · RHSA-2023:3277
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
kernel-0:3.10.0-1062.72.1.el7
Fixed · RHSA-2023:3277
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:3278
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8
Fixed · RHSA-2023:2736
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kernel-0:4.18.0-147.80.1.el8_1
Fixed · RHSA-2023:0856
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:0858
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.105.1.el8_2
Fixed · RHSA-2023:1559
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.105.1.el8_2
Fixed · RHSA-2023:1559
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.105.1.rt13.156.el8_2
Fixed · RHSA-2023:1560
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.105.1.el8_2
Fixed · RHSA-2023:1559
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:1666
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-0:4.18.0-305.82.1.el8_4
Fixed · RHSA-2023:1221
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-rt-0:4.18.0-305.82.1.rt7.154.el8_4
Fixed · RHSA-2023:1220
Red Hat Enterprise Linux 8.4 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:1251
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.57.1.el8_6
Fixed · RHSA-2023:3388
Red Hat Enterprise Linux 8.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:3431
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.18.1.el9_1
Fixed · RHSA-2023:0951
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.18.1.el9_1
Fixed · RHSA-2023:0951
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-162.18.1.rt21.181.el9_1
Fixed · RHSA-2023:0979
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2023:1008
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.49.1.el9_0
Fixed · RHSA-2023:1202
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.49.1.rt21.120.el9_0
Fixed · RHSA-2023:1203
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:1435
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.57.1.el8_6
Fixed · RHSA-2023:3388
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.3-202306050942_8.6
Fixed · RHSA-2023:3491
Red Hat Enterprise Linux 6
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.95.1.el7 | Fixed | RHSA-2023:4151 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.95.1.rt56.1241.el7 | Fixed | RHSA-2023:4150 |
| Red Hat Enterprise Linux 7 | kpatch-patch | Fixed | RHSA-2023:4215 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.111.1.el7 | Fixed | RHSA-2023:4020 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | kernel-0:3.10.0-957.104.1.el7 | Fixed | RHSA-2023:4021 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | kernel-0:3.10.0-1062.72.1.el7 | Fixed | RHSA-2023:3277 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | kernel-0:3.10.0-1062.72.1.el7 | Fixed | RHSA-2023:3277 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | kernel-0:3.10.0-1062.72.1.el7 | Fixed | RHSA-2023:3277 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:3278 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8 | Fixed | RHSA-2023:2736 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kernel-0:4.18.0-147.80.1.el8_1 | Fixed | RHSA-2023:0856 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:0858 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.105.1.el8_2 | Fixed | RHSA-2023:1559 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.105.1.el8_2 | Fixed | RHSA-2023:1559 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.105.1.rt13.156.el8_2 | Fixed | RHSA-2023:1560 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.105.1.el8_2 | Fixed | RHSA-2023:1559 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:1666 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-0:4.18.0-305.82.1.el8_4 | Fixed | RHSA-2023:1221 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-rt-0:4.18.0-305.82.1.rt7.154.el8_4 | Fixed | RHSA-2023:1220 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:1251 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.57.1.el8_6 | Fixed | RHSA-2023:3388 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:3431 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.18.1.el9_1 | Fixed | RHSA-2023:0951 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.18.1.el9_1 | Fixed | RHSA-2023:0951 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-162.18.1.rt21.181.el9_1 | Fixed | RHSA-2023:0979 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2023:1008 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.49.1.el9_0 | Fixed | RHSA-2023:1202 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.49.1.rt21.120.el9_0 | Fixed | RHSA-2023:1203 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:1435 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.57.1.el8_6 | Fixed | RHSA-2023:3388 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.3-202306050942_8.6 | Fixed | RHSA-2023:3491 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is rated between Moderate and Important (similar to the CVE-2022-45934) because of no known attack, and the attack would be complex. Anyway, consider this CVE-2022-3564 as Important because the use-after-free can potentially lead to privilege escalation or a potential remote system crash (and currently, a read after-free that in most cases would not lead to a remote system crash).
Red Hat mitigation
To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the Customer Portal at https://access.redhat.com/solutions/2682931. Alternatively, Bluetooth can be disabled within the hardware or at BIOS level which will also provide an effective mitigation as the kernel will not be able to detect that Bluetooth hardware is present on the system.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-3564 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2150999 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=89f9f3cb86b1c63badaf392a83dd661d56cc50b1 Patch
- https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3564
- https://security.netapp.com/advisory/ntap-20221223-0001/ Third Party Advisory
- https://vuldb.com/?id.211087 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3564
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3564 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2150999 | Issue Tracking | |
| https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=89f9f3cb86b1c63badaf392a83dd661d56cc50b1 | Patch | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3564 | ||
| https://security.netapp.com/advisory/ntap-20221223-0001/ | Third Party Advisory | |
| https://vuldb.com/?id.211087 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3564 |
Change history (0)
No recorded changes yet.