GSD-2022-1004009

    Dashboard / Vulnerabilities / GSD-2022-1004009

    GSD-2022-1004009

    Published: 28 Jun 2022Last Modified: 22 Feb 2023

    Summary: Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout

    Details: Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v4.14.283 by commit 7d61dbd7311ab978d8ddac1749a758de4de00374, it was introduced in version v4.14.247 by commit 0115a66ebb44bd9127ccb58cf43ed23c795eb1f0. For more details please see the references link.

    References:

    Affected packages

    Package

    Name: Kernel

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 0115a66ebb44bd9127ccb58cf43ed23c795eb1f0
    Fixed -None

    Affected versions

    v4.14.247
    v4.14.248
    v4.14.249
    v4.14.250
    v4.14.251
    v4.14.252
    v4.14.253
    v4.14.254
    v4.14.255
    v4.14.256
    v4.14.257
    v4.14.258
    v4.14.259
    v4.14.260
    v4.14.261
    v4.14.262
    v4.14.263
    v4.14.264
    v4.14.265
    v4.14.266
    v4.14.267
    v4.14.268
    v4.14.269
    v4.14.270
    v4.14.271
    v4.14.272
    v4.14.273
    v4.14.274
    v4.14.275
    v4.14.276
    v4.14.277
    v4.14.278
    v4.14.279
    v4.14.280
    v4.14.281
    v4.14.282

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2022-1004009 | CVE-DB