GSD-2022-1004076
Dashboard / Vulnerabilities / GSD-2022-1004076
GSD-2022-1004076
Published: 28 Jun 2022Last Modified: 22 Feb 2023
Summary: Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout
Details: Bluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v4.9.318 by commit 9de3dc09e56f8deacd2bdbf4cecb71e11a312405, it was introduced in version v4.9.283 by commit 22c66af08230a7030bdb88accffaec3424695631. For more details please see the references link.
References:
Affected packages
Package
Name: Kernel
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 22c66af08230a7030bdb88accffaec3424695631
Fixed -None
Affected versions
v4.9.283
v4.9.284
v4.9.285
v4.9.286
v4.9.287
v4.9.288
v4.9.289
v4.9.290
v4.9.291
v4.9.292
v4.9.293
v4.9.294
v4.9.295
v4.9.296
v4.9.297
v4.9.298
v4.9.299
v4.9.300
v4.9.301
v4.9.302
v4.9.303
v4.9.304
v4.9.305
v4.9.306
v4.9.307
v4.9.308
v4.9.309
v4.9.310
v4.9.311
v4.9.312
v4.9.313
v4.9.314
v4.9.315
v4.9.316
v4.9.317
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
