GSD-2022-1003600

Source
https://data.gsd.id/GSD-2022-1003600
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1003xxx/GSD-2022-1003600.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2022-1003600
Published
2022-06-28T19:30:39.187666Z
Modified
2023-02-22T07:30:50.967702Z
Summary
Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout
Details

Bluetooth: fix dangling scoconn and use-after-free in scosock_timeout

This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v5.10.121 by commit 36c644c63bfcaee2d3a426f45e89a9cd09799318, it was introduced in version v5.10.65 by commit 059c2c09f4b7f97711d0d8eaa0b9877f5e7d0a75. For more details please see the references link.

References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
Events
Introduced
059c2c09f4b7f97711d0d8eaa0b9877f5e7d0a75
Limit
36c644c63bfcaee2d3a426f45e89a9cd09799318

Affected versions

v5.*
v5.10.100
v5.10.101
v5.10.102
v5.10.103
v5.10.104
v5.10.105
v5.10.106
v5.10.107
v5.10.108
v5.10.109
v5.10.110
v5.10.111
v5.10.112
v5.10.113
v5.10.114
v5.10.115
v5.10.116
v5.10.117
v5.10.118
v5.10.119
v5.10.120
v5.10.65
v5.10.66
v5.10.67
v5.10.68
v5.10.69
v5.10.70
v5.10.71
v5.10.72
v5.10.73
v5.10.74
v5.10.75
v5.10.76
v5.10.77
v5.10.78
v5.10.79
v5.10.80
v5.10.81
v5.10.82
v5.10.83
v5.10.84
v5.10.85
v5.10.86
v5.10.87
v5.10.88
v5.10.89
v5.10.90
v5.10.91
v5.10.92
v5.10.93
v5.10.94
v5.10.95
v5.10.96
v5.10.97
v5.10.98
v5.10.99

Database specific

source
"https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1003xxx/GSD-2022-1003600.json"