Linux Kernel Bluetooth l1oip_core.c del_timer use after free
Published Oct 17, 2022
7.8
HIGHCVSS 3.1
EPSS 0.35%
Description
A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211088.
Affected products
- ≥ 2.6.27 · < 4.9.331
- ≥ 4.10 · < 4.14.296
- ≥ 4.15 · < 4.19.262
- ≥ 4.20 · < 5.4.220
- ≥ 5.5 · < 5.10.150
- ≥ 5.11 · < 5.15.75
- ≥ 5.16 · < 5.19.17
- ≥ 6.0 · < 6.0.3
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.el8_10
Fixed · RHSA-2024:3138
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.rt7.342.el8_10
Fixed · RHSA-2024:2950
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.el8_10 | Fixed | RHSA-2024:3138 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.rt7.342.el8_10 | Fixed | RHSA-2024:2950 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, prevent the l1oip module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-3565 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2150953 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=2568a7e0832ee30b0a351016d03062ab4e0e0a3f PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3565
- https://vuldb.com/?id.211088 Permissions Required
- https://www.cve.org/CVERecord?id=CVE-2022-3565
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3565 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2150953 | Issue Tracking | |
| https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=2568a7e0832ee30b0a351016d03062ab4e0e0a3f | PatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3565 | ||
| https://vuldb.com/?id.211088 | Permissions Required | |
| https://www.cve.org/CVERecord?id=CVE-2022-3565 |
Change history (0)
No recorded changes yet.