GSD-2022-1002755

Source
https://data.gsd.id/GSD-2022-1002755
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1002xxx/GSD-2022-1002755.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2022-1002755
Published
2022-06-28T18:15:42.068872Z
Modified
2023-02-22T09:11:13.940430Z
Summary
Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout
Details

Bluetooth: fix dangling scoconn and use-after-free in scosock_timeout

This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v5.18.3 by commit 99df16007f4bbf9abfc3478cb17d10f0d7f8906e, it was introduced in version v5.15 by commit e1dee2c1de2b4dd00eb44004a4bda6326ed07b59. For more details please see the references link.

References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
Events
Introduced
e1dee2c1de2b4dd00eb44004a4bda6326ed07b59
Limit
99df16007f4bbf9abfc3478cb17d10f0d7f8906e

Affected versions

v5.*
v5.14
v5.14-rc2
v5.14-rc3
v5.14-rc4
v5.14-rc5
v5.14-rc6
v5.14-rc7
v5.15
v5.15-rc1
v5.15-rc2
v5.15-rc3
v5.15-rc4
v5.15-rc5
v5.15-rc6
v5.15-rc7
v5.16
v5.16-rc1
v5.16-rc2
v5.16-rc3
v5.16-rc4
v5.16-rc5
v5.16-rc6
v5.16-rc7
v5.16-rc8
v5.17
v5.17-rc1
v5.17-rc2
v5.17-rc3
v5.17-rc4
v5.17-rc5
v5.17-rc6
v5.17-rc7
v5.17-rc8
v5.18
v5.18-rc1
v5.18-rc2
v5.18-rc3
v5.18-rc4
v5.18-rc5
v5.18-rc6
v5.18-rc7
v5.18.1
v5.18.2

Database specific

source
"https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1002xxx/GSD-2022-1002755.json"