CVE-2022-50233

MEDIUM

Linux Kernel 4.14-6.0 - Denial of Service via Bluetooth EIR String Length Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix using strlen with hdev->{dev_name,short_name} Both dev_name and short_name are not guaranteed to be NULL terminated so this instead use strnlen and then attempt to determine if the resulting string needs to be truncated or not.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (5)
Linux/Linux < 4.14
Linux/Linux 4.14
Linux/Linux 4c3dbb2c312c9fafbac30d98c523b8b1f3455d78 - dd7b8cdde098cf9f7c8de409b5b7bbb98f97be80
Linux/Linux 6.0
linux/linux_kernel 4.14 - 6.0
Published Aug 09, 2025
Tracked Since Feb 18, 2026