← Back to CVE List
Vulnerability Intelligence Report
Info Leak in l2cap_core in the Linux Kernel

CVE-2022-42896

There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit  https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url

No Active Exploit Signals
CVSS Base Score
8.0
HIGH
Exploitability:1.7
Impact Score:5.8
EPSS Probability:2.01%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-416 ↗CWE-416 Use After Free

Affected Products & Versions

Vendor Product Affected Versions
Linux Linux Kernel 3.0.0 <= 711f8c3fb3db61897080468586b970c87c61d9e4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.014%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGoogle LLC · Vendor · USA
Reserved2022-10-12T18:30:19
Published2022-11-23T14:11:56
Patch Date2022-11-02
Last Updated2025-04-21T13:45:57

LINK COPIED TO CLIPBOARD