CVE-2022-3640: Linux Kernel Bluetooth l2cap_core.c l2cap_conn_del use after free
A use-after-free in the function l2capconndel of the file net/bluetooth/l2capcore.c of the component Bluetooth in Linux Kernel could allow a remote authenticated attacker from within the local network to cause an unknown impact.
Other sources
A vulnerability was found in the Linux Kernel in the l2capconndel in net/bluetooth/l2capcore.c function in the Bluetooth component. This issue leads to a use-after-free problem.
A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2capconndel of the file net/bluetooth/l2capcore.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211944.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-3640?
CVE-2022-3640 is considered a significant security vulnerability due to its potential exploitation by remote authenticated attackers.
How do I fix CVE-2022-3640?
To fix CVE-2022-3640, you should update to the patched kernel versions provided by your operating system vendor.
Which systems are affected by CVE-2022-3640?
CVE-2022-3640 affects various versions of the Linux Kernel, particularly those up to 5.14.0-284.11.1 and similar distributions.
What type of vulnerability is CVE-2022-3640?
CVE-2022-3640 is classified as a use-after-free vulnerability in the Bluetooth component of the Linux Kernel.
Can CVE-2022-3640 impact my network security?
Yes, CVE-2022-3640 can potentially allow remote authenticated attackers to disrupt network security if properly exploited.