CVE-2022-3806: Bluetooth HCI Error Handling Double Free
Published Jan 19, 2023
·Updated
Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.
Affected Software
1 affected component
zephyrproject zephyr<=3.2.0
Event History
Jan 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 25, 2023
Data Sourced
via NVD·02:01 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-3806?
CVE-2022-3806 is a vulnerability that occurs due to inconsistent handling of error cases in bluetooth hci, which may lead to a double free condition of a network buffer.
2
What is the severity of CVE-2022-3806?
The severity of CVE-2022-3806 is critical, with a severity score of 9.8.
3
Which software versions are affected by CVE-2022-3806?
Zephyrproject Zephyr versions up to and including 3.2.0 are affected by CVE-2022-3806.
4
How can CVE-2022-3806 be fixed?
To fix CVE-2022-3806, it is recommended to update to a version of Zephyrproject Zephyr that is higher than 3.2.0.
5
Where can I find more information about CVE-2022-3806?
More information about CVE-2022-3806 can be found in the Zephyrproject Zephyr security advisory at: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-w525-fm68-ppq3