CVE-2022-49138

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
26/02/2025
Last modified:
23/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: hci_event: Ignore multiple conn complete events<br /> <br /> When one of the three connection complete events is received multiple<br /> times for the same handle, the device is registered multiple times which<br /> leads to memory corruptions. Therefore, consequent events for a single<br /> connection are ignored.<br /> <br /> The conn-&gt;state can hold different values, therefore HCI_CONN_HANDLE_UNSET<br /> is introduced to identify new connections. To make sure the events do not<br /> contain this or another invalid handle HCI_CONN_HANDLE_MAX and checks<br /> are introduced.<br /> <br /> Buglink: https://bugzilla.kernel.org/show_bug.cgi?id=215497

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.17.3 (excluding)