Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3563

Опубликовано: 23 июн. 2022
Источник: redhat
CVSS3: 5.7
EPSS Низкий

Описание

A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigned to this vulnerability.

A vulnerability has been found in BlueZ. This issue affects the read_50_controller_cap_complete function of the tools/mgmt-tester.c file in the BlueZ component. A manipulation of the cap_len argument leads to null pointer dereference.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bluezOut of support scope
Red Hat Enterprise Linux 7bluezOut of support scope
Red Hat Enterprise Linux 8bluezWill not fix
Red Hat Enterprise Linux 9bluezWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2150993bluez: NULL pointer dereference in read_50_controller_cap_complete() in tools/mgmt-tester.c

EPSS

Процентиль: 5%
0.00023
Низкий

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.5
ubuntu
больше 3 лет назад

A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigned to this vulnerability.

CVSS3: 3.5
nvd
больше 3 лет назад

A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigned to this vulnerability.

CVSS3: 5.7
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 3.5
debian
больше 3 лет назад

A vulnerability classified as problematic has been found in Linux Kern ...

suse-cvrf
около 3 лет назад

Security update for bluez

EPSS

Процентиль: 5%
0.00023
Низкий

5.7 Medium

CVSS3