CVE-2022-49138
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
26/02/2025
Last modified:
23/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Bluetooth: hci_event: Ignore multiple conn complete events<br />
<br />
When one of the three connection complete events is received multiple<br />
times for the same handle, the device is registered multiple times which<br />
leads to memory corruptions. Therefore, consequent events for a single<br />
connection are ignored.<br />
<br />
The conn->state can hold different values, therefore HCI_CONN_HANDLE_UNSET<br />
is introduced to identify new connections. To make sure the events do not<br />
contain this or another invalid handle HCI_CONN_HANDLE_MAX and checks<br />
are introduced.<br />
<br />
Buglink: https://bugzilla.kernel.org/show_bug.cgi?id=215497
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.17.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



