CVE-2022-3565
MEDIUMLinux Kernel 2.6.27-4.9.330 - Use-After-Free in Bluetooth l1oip_core.c del_timer
Title source: llmDescription
A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211088.
References (4)
Core 4
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html
Patch, Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=2568a7e0832ee30b0a351016d03062ab4e0e0a3f
Permissions Required
https://vuldb.com/?id.211088
Scores
CVSS v3
4.6
EPSS
0.0032
EPSS Percentile
23.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-119
CWE-662
Status
published
Products (1)
linux/linux_kernel
2.6.27 - 4.9.331
Published
Oct 17, 2022
Tracked Since
Feb 18, 2026