CVE-2022-50233
MEDIUMLinux Kernel 4.14-6.0 - Denial of Service via Bluetooth EIR String Length Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix using strlen with hdev->{dev_name,short_name} Both dev_name and short_name are not guaranteed to be NULL terminated so this instead use strnlen and then attempt to determine if the resulting string needs to be truncated or not.
References (1)
Core 1
Core References
Scores
CVSS v3
5.5
EPSS
0.0013
EPSS Percentile
3.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (5)
Linux/Linux
< 4.14
Linux/Linux
4.14
Linux/Linux
4c3dbb2c312c9fafbac30d98c523b8b1f3455d78 - dd7b8cdde098cf9f7c8de409b5b7bbb98f97be80
Linux/Linux
6.0
linux/linux_kernel
4.14 - 6.0
Published
Aug 09, 2025
Tracked Since
Feb 18, 2026