Vulnerability Description
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bluez | Bluez | < 5.63 |
| Fedoraproject | Fedora | 35 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2039807Issue TrackingPatchThird Party Advisory
- https://github.com/bluez/bluez/commit/591c546c536b42bef696d027f64aa22434f8c3f0PatchThird Party Advisory
- https://github.com/bluez/bluez/security/advisories/GHSA-479m-xcq5-9g2qExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202209-16Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2039807Issue TrackingPatchThird Party Advisory
- https://github.com/bluez/bluez/commit/591c546c536b42bef696d027f64aa22434f8c3f0PatchThird Party Advisory
- https://github.com/bluez/bluez/security/advisories/GHSA-479m-xcq5-9g2qExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00022.html
- https://security.gentoo.org/glsa/202209-16Third Party Advisory
FAQ
What is CVE-2022-0204?
CVE-2022-0204 is a vulnerability with a CVSS score of 8.8 (HIGH). A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to...
How severe is CVE-2022-0204?
CVE-2022-0204 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0204?
Check the references section above for vendor advisories and patch information. Affected products include: Bluez Bluez, Fedoraproject Fedora, Debian Debian Linux.