Wind River Support Network

HomeDefectsLIN1022-2337
Fixed

LIN1022-2337 : Security Advisory - linux - CVE-2022-42895

Created: Nov 6, 2022    Updated: Dec 12, 2022
Resolved Date: Dec 7, 2022
Found In Version: 10.22.33.1
Fix Version: 10.22.33.3
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past commit https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e https://www.google.com/url

https://nvd.nist.gov/vuln/detail/CVE-2022-42895

CVEs


Live chat
Online