In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: fix null ptr deref on hcisyncconncompleteevt
This event is just specified for SCO and eSCO link types. On the reception of a HCISynchronousConnection_Complete for a BDADDR of an existing LE connection, LE link type and a status that triggers the second case of the packet processing a NULL pointer dereference happens, as conn->link is NULL.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c1aa0dd52db4ce888be0bd820c3fa918d350ca0b",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-20386ab1",
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"245395213258018789650768360564266481486",
"220478674849082657912656333786969156640",
"115260443035551403519296559840594186102"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f61c23e73dc653b957781066abfa8105c3fa3f5b",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-2b0c79e4",
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"322502383720212625765998489862499154895",
"211884295890284912666587878346012082485",
"85470184356688659262676584121123797357"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c1aa0dd52db4ce888be0bd820c3fa918d350ca0b",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-2e81bd58",
"target": {
"function": "hci_sync_conn_complete_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1503.0,
"function_hash": "216934202310752235553324431574858416296"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1c1291a84e94f6501644634c97544bb8291e9a1a",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-854a448c",
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"245395213258018789650768360564266481486",
"220478674849082657912656333786969156640",
"115260443035551403519296559840594186102"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f61c23e73dc653b957781066abfa8105c3fa3f5b",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-b183e08d",
"target": {
"function": "hci_sync_conn_complete_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1502.0,
"function_hash": "116832433522954336514696245131281973816"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1c1291a84e94f6501644634c97544bb8291e9a1a",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-b67f3119",
"target": {
"function": "hci_sync_conn_complete_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1179.0,
"function_hash": "67364807077194728080209703329895856789"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0f9db1209f59844839175b5b907d3778cafde93d",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-cf18e23e",
"target": {
"function": "hci_sync_conn_complete_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1503.0,
"function_hash": "216934202310752235553324431574858416296"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3afee2118132e93e5f6fa636dfde86201a860ab3",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-d1e83e4a",
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"322502383720212625765998489862499154895",
"211884295890284912666587878346012082485",
"85470184356688659262676584121123797357"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0f9db1209f59844839175b5b907d3778cafde93d",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-e5e86702",
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"245395213258018789650768360564266481486",
"220478674849082657912656333786969156640",
"115260443035551403519296559840594186102"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3afee2118132e93e5f6fa636dfde86201a860ab3",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2022-49139-eebde51f",
"target": {
"function": "hci_sync_conn_complete_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1502.0,
"function_hash": "116832433522954336514696245131281973816"
},
"signature_type": "Function"
}
]