Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3564

Опубликовано: 04 окт. 2022
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.

A use-after-free flaw was found in the Linux kernel’s L2CAP bluetooth functionality in how a user triggers a race condition by two malicious flows in the L2CAP bluetooth packets. This flaw allows a local or bluetooth connection user to crash the system or potentially escalate privileges.

Отчет

This issue is rated between Moderate and Important (similar to the CVE-2022-45934) because of no known attack, and the attack would be complex. Anyway, consider this CVE-2022-3564 as Important because the use-after-free can potentially lead to privilege escalation or a potential remote system crash (and currently, a read after-free that in most cases would not lead to a remote system crash).

Меры по смягчению последствий

To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the Customer Portal at https://access.redhat.com/solutions/2682931. Alternatively, Bluetooth can be disabled within the hardware or at BIOS level which will also provide an effective mitigation as the kernel will not be able to detect that Bluetooth hardware is present on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2023:415018.07.2023
Red Hat Enterprise Linux 7kernelFixedRHSA-2023:415118.07.2023
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2023:421519.07.2023
Red Hat Enterprise Linux 7.4 Advanced Update SupportkernelFixedRHSA-2023:402011.07.2023
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)kernelFixedRHSA-2023:402111.07.2023
Red Hat Enterprise Linux 7.7 Advanced Update SupportkernelFixedRHSA-2023:327723.05.2023
Red Hat Enterprise Linux 7.7 Telco Extended Update SupportkernelFixedRHSA-2023:327723.05.2023
Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionskernelFixedRHSA-2023:327723.05.2023
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutionskpatch-patchFixedRHSA-2023:327823.05.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2150999kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c

EPSS

Процентиль: 20%
0.00063
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.

CVSS3: 5.5
nvd
больше 2 лет назад

A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.

CVSS3: 5.5
debian
больше 2 лет назад

A vulnerability classified as critical was found in Linux Kernel. Affe ...

suse-cvrf
больше 2 лет назад

Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP2)

suse-cvrf
больше 2 лет назад

Security update for the Linux Kernel (Live Patch 25 for SLE 15 SP2)

EPSS

Процентиль: 20%
0.00063
Низкий

7.1 High

CVSS3