GSD-2022-1003771

    Dashboard / Vulnerabilities / GSD-2022-1003771

    GSD-2022-1003771

    Published: 28 Jun 2022Last Modified: 22 Feb 2023

    Summary: Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout

    Details: Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v5.4.198 by commit 6f55fac0af3531cf60d11369454c41f5fc81ab3f, it was introduced in version v5.4.146 by commit 5ccb04c6e1fb7b97fa2e1785b67c3a1cb3527ef7. For more details please see the references link.

    References:

    Affected packages

    Package

    Name: Kernel

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 5ccb04c6e1fb7b97fa2e1785b67c3a1cb3527ef7
    Fixed -None

    Affected versions

    v5.4.146
    v5.4.147
    v5.4.148
    v5.4.149
    v5.4.150
    v5.4.151
    v5.4.152
    v5.4.153
    v5.4.154
    v5.4.155
    v5.4.156
    v5.4.157
    v5.4.158
    v5.4.159
    v5.4.160
    v5.4.161
    v5.4.162
    v5.4.163
    v5.4.164
    v5.4.165
    v5.4.166
    v5.4.167
    v5.4.168
    v5.4.169
    v5.4.170
    v5.4.171
    v5.4.172
    v5.4.173
    v5.4.174
    v5.4.175
    v5.4.176
    v5.4.177
    v5.4.178
    v5.4.179
    v5.4.180
    v5.4.181
    v5.4.182
    v5.4.183
    v5.4.184
    v5.4.185
    v5.4.186
    v5.4.187
    v5.4.188
    v5.4.189
    v5.4.190
    v5.4.191
    v5.4.192
    v5.4.193
    v5.4.194
    v5.4.195
    v5.4.196
    v5.4.197

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2022-1003771 | CVE-DB