Back

MEDIUM

Info Leak in l2cap_core in the Linux Kernel

Published Nov 23, 2022

Description

There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past commit  https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e https://www.google.com/url

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 6 is not affected by this flaw as it did not include support for parsing Extended Flow Specification option in L2CAP Config Request (upstream commit 42dceae2).

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Nov 23, 2022
Updated Apr 21, 2025
Reserved Oct 12, 2022
CISA Vulnrichment
Updated Apr 21, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 3, 2022
ENISA EUVD
Assigner Google
Published Nov 23, 2022
Updated Apr 21, 2025
Exploited since n/a
EUVD-2022-45953