CVE-2016-9798: Use After Free
Published Dec 3, 2016
·Updated
In BlueZ 5.42, a use-after-free was identified in "confopt" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
Affected Software
1 affected component
bluez bluez=5.42
Event History
Dec 3, 2016
CVE Published
via MITRE·06:28 AM
Data Sourced
via MITRE·06:28 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9798?
CVE-2016-9798 has been classified as a medium severity vulnerability due to its potential to cause system crashes.
2
How do I fix CVE-2016-9798?
To fix CVE-2016-9798, you should upgrade to a later version of BlueZ that has patched the use-after-free vulnerability.
3
What systems are affected by CVE-2016-9798?
CVE-2016-9798 specifically affects BlueZ version 5.42.
4
What is the impact of CVE-2016-9798?
The impact of CVE-2016-9798 includes the potential crash of hcidump when processing a corrupted dump file.
5
Is CVE-2016-9798 a known vulnerability?
Yes, CVE-2016-9798 is a well-documented vulnerability that has been publicly disclosed and reported.