GSD-2022-1003897

Source
https://data.gsd.id/GSD-2022-1003897
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1003xxx/GSD-2022-1003897.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2022-1003897
Published
2022-06-28T19:59:55.387430Z
Modified
2023-02-22T09:54:59.461157Z
Summary
Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout
Details

Bluetooth: fix dangling scoconn and use-after-free in scosock_timeout

This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v4.19.247 by commit 390d82733a953c1fabf3de9c9618091a7a9c90a6, it was introduced in version v4.19.207 by commit bc4b08383046f3282b6fa58cfcef05bd13e52b93. For more details please see the references link.

References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
Events
Introduced
bc4b08383046f3282b6fa58cfcef05bd13e52b93
Limit
390d82733a953c1fabf3de9c9618091a7a9c90a6

Affected versions

v4.*
v4.19.207
v4.19.208
v4.19.209
v4.19.210
v4.19.211
v4.19.212
v4.19.213
v4.19.214
v4.19.215
v4.19.216
v4.19.217
v4.19.218
v4.19.219
v4.19.220
v4.19.221
v4.19.222
v4.19.223
v4.19.224
v4.19.225
v4.19.226
v4.19.227
v4.19.228
v4.19.229
v4.19.230
v4.19.231
v4.19.232
v4.19.233
v4.19.234
v4.19.235
v4.19.236
v4.19.237
v4.19.238
v4.19.239
v4.19.240
v4.19.241
v4.19.242
v4.19.243
v4.19.244
v4.19.245
v4.19.246

Database specific

source
"https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1003xxx/GSD-2022-1003897.json"