UBUNTU-CVE-2022-42896
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-42896
UBUNTU-CVE-2022-42896
Summary:
Details: There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url
References: https://ubuntu.com/security/CVE-2022-42896, https://git.kernel.org/linus/711f8c3fb3db61897080468586b970c87c61d9e4, https://github.com/google/security-research/security/advisories/GHSA-pf87-6c9q-jvm4, https://ubuntu.com/security/notices/USN-5780-1, https://ubuntu.com/security/notices/USN-5783-1, https://ubuntu.com/security/notices/USN-5794-1, https://ubuntu.com/security/notices/USN-5802-1, https://ubuntu.com/security/notices/USN-5803-1, https://ubuntu.com/security/notices/USN-5804-1, https://ubuntu.com/security/notices/USN-5804-2, https://ubuntu.com/security/notices/USN-5808-1, https://ubuntu.com/security/notices/USN-5809-1, https://ubuntu.com/security/notices/USN-5813-1, https://ubuntu.com/security/notices/USN-5814-1, https://ubuntu.com/security/notices/USN-5829-1, https://ubuntu.com/security/notices/USN-5830-1, https://ubuntu.com/security/notices/USN-5831-1, https://ubuntu.com/security/notices/USN-5832-1, https://ubuntu.com/security/notices/USN-5860-1, https://ubuntu.com/security/notices/USN-5861-1, https://ubuntu.com/security/notices/USN-5863-1, https://ubuntu.com/security/notices/USN-5875-1, https://ubuntu.com/security/notices/USN-5877-1, https://ubuntu.com/security/notices/USN-5879-1, https://ubuntu.com/security/notices/USN-5914-1, https://ubuntu.com/security/notices/USN-5918-1, https://www.cve.org/CVERecord?id=CVE-2022-42896
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
