CVE-2022-3564: Linux Kernel Bluetooth l2cap_core.c l2cap_reassemble_sdu use after free
A use-after-free in the function l2capreassemblesdu of the file net/bluetooth/l2capcore.c of the component Bluetooth in Linux Kernel could allow a remote authenticated attacker from within the local network to cause an unknown impact.
Other sources
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2capreassemblesdu of the file net/bluetooth/l2capcore.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3564?
CVE-2022-3564 is classified as a critical vulnerability.
How can I fix CVE-2022-3564?
To fix CVE-2022-3564, update your Bluetooth stack in the Linux Kernel to the latest version that contains the patch.
Which software is affected by CVE-2022-3564?
CVE-2022-3564 affects various versions of the Linux Kernel as well as IBM QRadar SIEM version 7.5.0 UP6.
What type of vulnerability is CVE-2022-3564?
CVE-2022-3564 is a use-after-free vulnerability found in the Bluetooth component of the Linux Kernel.
Can CVE-2022-3564 be exploited remotely?
Yes, CVE-2022-3564 can potentially be exploited by a remote authenticated attacker within the local network.