Bug 2150993 (CVE-2022-3563) - CVE-2022-3563 bluez: NULL pointer dereference in read_50_controller_cap_complete() in tools/mgmt-tester.c
Summary: CVE-2022-3563 bluez: NULL pointer dereference in read_50_controller_cap_compl...
Keywords:
Status: NEW
Alias: CVE-2022-3563
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2150994 2151072 2151073
Blocks: 2150995
TreeView+ depends on / blocked
 
Reported: 2022-12-05 19:44 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-07-07 08:29 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability has been found in BlueZ. This issue affects the read_50_controller_cap_complete function of the tools/mgmt-tester.c file in the BlueZ component. A manipulation of the cap_len argument leads to null pointer dereference.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2022-12-05 19:44:44 UTC
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigned to this vulnerability.

Reference:
https://vuldb.com/?id.211086

Upstream patch:
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=e3c92f1f786f0b55440bd908b55894d0c792cf0e

Comment 1 Guilherme de Almeida Suckevicz 2022-12-05 19:44:58 UTC
Created bluez tracking bugs for this issue:

Affects: fedora-all [bug 2150994]


Note You need to log in before you can comment on or make changes to this bug.