First published: Mon Oct 17 2022(Updated: )
A use-after-free in the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth in Linux Kernel could allow a remote authenticated attacker from within the local network to cause an unknown impact.
Credit: cna@vuldb.com cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <6.1 | 6.1 |
Linux kernel | >=2.6.27<4.9.331 | |
Linux kernel | >=4.10<4.14.296 | |
Linux kernel | >=4.15<4.19.262 | |
Linux kernel | >=4.20<5.4.220 | |
Linux kernel | >=5.5<5.10.150 | |
Linux kernel | >=5.11<5.15.75 | |
Linux kernel | >=5.16<5.19.17 | |
Linux kernel | >=6.0<6.0.3 | |
Linux Kernel | >=2.6.27<4.9.331 | |
Linux Kernel | >=4.10<4.14.296 | |
Linux Kernel | >=4.15<4.19.262 | |
Linux Kernel | >=4.20<5.4.220 | |
Linux Kernel | >=5.5<5.10.150 | |
Linux Kernel | >=5.11<5.15.75 | |
Linux Kernel | >=5.16<5.19.17 | |
Linux Kernel | >=6.0<6.0.3 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.21-1 6.12.22-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3565 is classified as a high-severity vulnerability due to its potential for exploitation through use after free in the Linux Kernel.
CVE-2022-3565 affects Linux Kernel versions from 2.6.27 up to but not including versions 6.1 and those within specific ranges outlined in the vulnerability report.
To fix CVE-2022-3565, apply the recommended patches or upgrade to the updated versions of the Linux Kernel specified in the vulnerability details.
CVE-2022-3565 primarily affects the del_timer function within the ISDN over IP tunnel in the Linux Kernel.
As of the latest updates, there is no confirmed evidence that CVE-2022-3565 is being actively exploited in the wild.