Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout
Published Feb 26, 2025
7.8
HIGHCVSS 3.1
EPSS 0.28%
Description
Connecting the same socket twice consecutively in sco_sock_connect() could lead to a race condition where two sco_conn objects are created but only one is associated with the socket. If the socket is closed before the SCO connection is established, the timer associated with the dangling sco_conn object won't be canceled. As the sock object is being freed, the use-after-free problem happens when the timer callback function sco_sock_timeout() accesses the socket. Here's the call trace:
dump_stack+0x107/0x163 ? refcount_inc+0x1c/ print_address_description.constprop.0+0x1c/0x47e ? refcount_inc+0x1c/0x7b kasan_report+0x13a/0x173 ? refcount_inc+0x1c/0x7b check_memory_region+0x132/0x139 refcount_inc+0x1c/0x7b sco_sock_timeout+0xb2/0x1ba process_one_work+0x739/0xbd1 ? cancel_delayed_work+0x13f/0x13f ? __raw_spin_lock_init+0xf0/0xf0 ? to_kthread+0x59/0x85 worker_thread+0x593/0x70e kthread+0x346/0x35a ? drain_workqueue+0x31a/0x31a ? kthread_bind+0x4b/0x4b ret_from_fork+0x1f/0x30
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- ≥ 4.14.247, < 4.14.283
- ≥ 4.19.207, < 4.19.247
- ≥ 4.4.284, < 4.5
- ≥ 4.9.283, < 4.9.318
- ≥ 5.10.65, < 5.10.121
- ≥ 5.13.17, < 5.14
- ≥ 5.14.4, < 5.15
- ≥ 5.4.146, < 5.4.198
-
Affected
- 5.15
Unaffected
- ≥ 0, < 5.15
- ≥ 4.14.283, ≤ 4.14.*
- ≥ 4.19.247, ≤ 4.19.*
- ≥ 4.9.318, ≤ 4.9.*
- ≥ 5.10.121, ≤ 5.10.*
- ≥ 5.15.46, ≤ 5.15.*
- ≥ 5.17.14, ≤ 5.17.*
- ≥ 5.18.3, ≤ 5.18.*
- 5.19
- ≥ 5.4.198, ≤ 5.4.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 4.4.284 · < 4.5
- ≥ 4.9.238 · < 4.9.318
- ≥ 4.14.247 · < 4.14.283
- ≥ 4.19.207 · < 4.19.247
- ≥ 5.4.146 · < 5.4.198
- ≥ 5.10.65 · < 5.10.121
- ≥ 5.13.17 · < 5.14
- ≥ 5.14.4 · < 5.15.46
- ≥ 5.16 · < 5.17.14
- ≥ 5.18 · < 5.18.3
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has assigned this vulnerability a Moderate severity rating with a CVSS score of 5.5. This assessment is based on the following key factors: * It is impossible to create sco_conn objects without physical access to both the server and client systems. * The dangling timer can cause a resource consumption attack, but there is no risk of any data leaks. * There is no loss of integrity, as even in case of successful exploitation, there is no data exchanged between the client and the server.
References (15)
- https://access.redhat.com/security/cve/CVE-2022-49474 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2348082 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-54755 Advisory
- https://git.kernel.org/stable/c/36c644c63bfcaee2d3a426f45e89a9cd09799318 Patch
- https://git.kernel.org/stable/c/390d82733a953c1fabf3de9c9618091a7a9c90a6 Patch
- https://git.kernel.org/stable/c/537f619dea4e3fa8ed1f8f938abffe3615794bcc Patch
- https://git.kernel.org/stable/c/65d347cb39e2e6bd0c2a745ad7c928998ebb0162 Patch
- https://git.kernel.org/stable/c/6f55fac0af3531cf60d11369454c41f5fc81ab3f Patch
- https://git.kernel.org/stable/c/7aa1e7d15f8a5b65f67bacb100d8fc033b21efa2 Patch
- https://git.kernel.org/stable/c/7d61dbd7311ab978d8ddac1749a758de4de00374 Patch
- https://git.kernel.org/stable/c/99df16007f4bbf9abfc3478cb17d10f0d7f8906e Patch
- https://git.kernel.org/stable/c/9de3dc09e56f8deacd2bdbf4cecb71e11a312405 Patch
- https://lore.kernel.org/linux-cve-announce/2025022603-CVE-2022-49474-ce0b@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49474
- https://www.cve.org/CVERecord?id=CVE-2022-49474
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data