Bluetooth: hci_conn: Fix crash on hci_create_cis_sync
Published Oct 1, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
When attempting to connect multiple ISO sockets without using DEFER_SETUP may result in the following crash:
BUG: KASAN: null-ptr-deref in hci_create_cis_sync+0x18b/0x2b0 Read of size 2 at addr 0000000000000036 by task kworker/u3:1/50
CPU: 0 PID: 50 Comm: kworker/u3:1 Not tainted 6.0.0-rc7-02243-gb84a13ff4eda #4373 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-1.fc36 04/01/2014 Workqueue: hci0 hci_cmd_sync_work Call Trace: <TASK> dump_stack_lvl+0x19/0x27 kasan_report+0xbc/0xf0 ? hci_create_cis_sync+0x18b/0x2b0 hci_create_cis_sync+0x18b/0x2b0 ? get_link_mode+0xd0/0xd0 ? __ww_mutex_lock_slowpath+0x10/0x10 ? mutex_lock+0xe0/0xe0 ? get_link_mode+0xd0/0xd0 hci_cmd_sync_work+0x111/0x190 process_one_work+0x427/0x650 worker_thread+0x87/0x750 ? process_one_work+0x650/0x650 kthread+0x14e/0x180 ? kthread_exit+0x50/0x50 ret_from_fork+0x22/0x30 </TASK>
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 6.0
Unaffected
- ≥ 0, < 6.0
- ≥ 6.0.16, ≤ 6.0.*
- ≥ 6.1.2, ≤ 6.1.*
- 6.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 6.0 · < 6.0.16
- ≥ 6.1 · < 6.1.2
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.152.1.el9_2
Fixed · RHSA-2026:0535
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.152.1.rt14.437.el9_2
Fixed · RHSA-2026:0534
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.152.1.el9_2 | Fixed | RHSA-2026:0535 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.152.1.rt14.437.el9_2 | Fixed | RHSA-2026:0534 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-50447 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2400804 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-32830 Advisory
- https://git.kernel.org/stable/c/09a3b0c9c7c6b10587fbb610b718014703cff341 Patch
- https://git.kernel.org/stable/c/50757a259ba78c4e938b5735e76ffec6cd0c942e Patch
- https://git.kernel.org/stable/c/a190cd9dc62d6ebeb679c1abe9dda4162dfefc84 Patch
- https://lore.kernel.org/linux-cve-announce/2025100115-CVE-2022-50447-4de6@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50447
- https://www.cve.org/CVERecord?id=CVE-2022-50447
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data