Bluetooth: Fix not cleanup led when bt_init fails
Published Oct 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
bt_init() calls bt_leds_init() to register led, but if it fails later, bt_leds_cleanup() is not called to unregister it.
This can cause panic if the argument "bluetooth-power" in text is freed and then another led_trigger_register() tries to access it:
BUG: unable to handle page fault for address: ffffffffc06d3bc0 RIP: 0010:strcmp+0xc/0x30 Call Trace: <TASK> led_trigger_register+0x10d/0x4f0 led_trigger_register_simple+0x7d/0x100 bt_init+0x39/0xf7 [bluetooth] do_one_initcall+0xd0/0x4e0
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.9StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.9
- Version 4.19.269StatusunaffectedConstraints<=4.19.*
- Version 5.10.159StatusunaffectedConstraints<=5.10.*
- Version 5.15.83StatusunaffectedConstraints<=5.15.*
- Version 5.4.227StatusunaffectedConstraints<=5.4.*
- Version 6.0.13StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.9 · < 4.19.269
- ≥ 4.20 · < 5.4.227
- ≥ 5.5 · < 5.10.159
- ≥ 5.11 · < 5.15.83
- ≥ 5.16 · < 6.0.13
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 22, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.24% (0.00236) | 13.23th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.24% (0.00235) | 14.25th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00029) | 5.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Oct 22, 2024 | 0.04% (0.00044) | 11.06th | v3 (v2023.03.01) |
References (11)
- https://access.redhat.com/security/cve/CVE-2022-48971 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320767 Issue Tracking
- https://git.kernel.org/stable/c/2c6cf0afc3856359e620e96edd952457d258e16c Patch
- https://git.kernel.org/stable/c/2f3957c7eb4e07df944169a3e50a4d6790e1c744 Patch
- https://git.kernel.org/stable/c/5ecf7cd6fde5e72c87122084cf00d63e35d8dd9f Patch
- https://git.kernel.org/stable/c/8a66c3a94285552f6a8e45d73b34ebbad11d388b Patch
- https://git.kernel.org/stable/c/e7b950458156d410509a08c41930b75e72985938 Patch
- https://git.kernel.org/stable/c/edf7284a98296369dd0891a0457eec37df244873 Patch
- https://lore.kernel.org/linux-cve-announce/2024102144-CVE-2022-48971-6025@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48971
- https://www.cve.org/CVERecord?id=CVE-2022-48971
Change history (0)
No recorded changes yet.