cve/2022/CVE-2022-42896.md
2024-08-11 18:44:53 +00:00

2.1 KiB

CVE-2022-42896

Description

There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit https://www.google.com/url 711f8c3fb3 https://www.google.com/url

POC

Reference

No PoCs from references.

Github