GSD-2022-1004076

Source
https://data.gsd.id/GSD-2022-1004076
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1004xxx/GSD-2022-1004076.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2022-1004076
Published
2022-06-28T20:19:09.186397Z
Modified
2023-02-22T05:15:29.488576Z
Summary
Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout
Details

Bluetooth: fix dangling scoconn and use-after-free in scosock_timeout

This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v4.9.318 by commit 9de3dc09e56f8deacd2bdbf4cecb71e11a312405, it was introduced in version v4.9.283 by commit 22c66af08230a7030bdb88accffaec3424695631. For more details please see the references link.

References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
Events
Introduced
22c66af08230a7030bdb88accffaec3424695631
Limit
9de3dc09e56f8deacd2bdbf4cecb71e11a312405

Affected versions

v4.*
v4.9.283
v4.9.284
v4.9.285
v4.9.286
v4.9.287
v4.9.288
v4.9.289
v4.9.290
v4.9.291
v4.9.292
v4.9.293
v4.9.294
v4.9.295
v4.9.296
v4.9.297
v4.9.298
v4.9.299
v4.9.300
v4.9.301
v4.9.302
v4.9.303
v4.9.304
v4.9.305
v4.9.306
v4.9.307
v4.9.308
v4.9.309
v4.9.310
v4.9.311
v4.9.312
v4.9.313
v4.9.314
v4.9.315
v4.9.316
v4.9.317

Database specific

source
"https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1004xxx/GSD-2022-1004076.json"