CVE-2022-49136

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
26/02/2025
Last modified:
25/03/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: hci_sync: Fix queuing commands when HCI_UNREGISTER is set<br /> <br /> hci_cmd_sync_queue shall return an error if HCI_UNREGISTER flag has<br /> been set as that means hci_unregister_dev has been called so it will<br /> likely cause a uaf after the timeout as the hdev will be freed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.17 (including) 5.17.3 (excluding)