Vulnerability Description
There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past commit https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e https://www.google.com/url
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2PatchThird Party Advisory
- https://kernel.dance/#b1a2cd50c0357f243b7435a732b4e62ba3157a2ePatchThird Party Advisory
- https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2PatchThird Party Advisory
- https://kernel.dance/#b1a2cd50c0357f243b7435a732b4e62ba3157a2ePatchThird Party Advisory
FAQ
What is CVE-2022-42895?
CVE-2022-42895 is a vulnerability with a CVSS score of 5.1 (MEDIUM). There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past comm...
How severe is CVE-2022-42895?
CVE-2022-42895 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-42895?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.