Info Leak in l2cap_core in the Linux Kernel
Published Nov 23, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.41%
Description
There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past commit https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e https://www.google.com/url
Affected products
-
- Version 3.0.0StatusaffectedConstraints
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | unaffected |
|
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.100.1.el8_6
Fixed · RHSA-2024:1877
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.55.1.el8_8
Fixed · RHSA-2024:2621
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.100.1.el8_6
Fixed · RHSA-2024:1877
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.100.1.el8_6 | Fixed | RHSA-2024:1877 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.55.1.el8_8 | Fixed | RHSA-2024:2621 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.100.1.el8_6 | Fixed | RHSA-2024:1877 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6 is not affected by this flaw as it did not include support for parsing Extended Flow Specification option in L2CAP Config Request (upstream commit 42dceae2).
References (8)
- https://access.redhat.com/security/cve/CVE-2022-42895 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2147356 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45953 Advisory
- https://github.com/google/security-research/security/advisories/GHSA-vccx-8h74-2357
- https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e PatchThird Party Advisory
- https://kernel.dance/#b1a2cd50c0357f243b7435a732b4e62ba3157a2e PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-42895
- https://www.cve.org/CVERecord?id=CVE-2022-42895
Change history (0)
No recorded changes yet.