VYPR
Unrated severityNVD Advisory· Published Feb 26, 2025· Updated May 4, 2025

Bluetooth: hci_sync: Fix queuing commands when HCI_UNREGISTER is set

CVE-2022-49136

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: Fix queuing commands when HCI_UNREGISTER is set

hci_cmd_sync_queue shall return an error if HCI_UNREGISTER flag has been set as that means hci_unregister_dev has been called so it will likely cause a uaf after the timeout as the hdev will be freed.

Affected products

72

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.