First published: Sun Nov 27 2022(Updated: )
An integer wraparound in the function l2cap_config_req in net/bluetooth/l2cap_core.c in Linux Kernel could allow a remote authenticated attacker from within the local network using L2CAP_CONF_REQ packets to cause an unknown impact.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=2.6.32<4.9.337 | |
Linux Kernel | >=4.10<4.14.303 | |
Linux Kernel | >=4.15<4.19.270 | |
Linux Kernel | >=4.20<5.4.229 | |
Linux Kernel | >=5.5<5.10.161 | |
Linux Kernel | >=5.11<5.15.85 | |
Linux Kernel | >=5.16<6.0.15 | |
Red Hat Fedora | =37 | |
NetApp H410C | ||
NetApp H410C Firmware | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
Debian Linux | =11.0 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 | |
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.135-1 6.12.25-1 6.12.27-1 | |
>=2.6.32<4.9.337 | ||
>=4.10<4.14.303 | ||
>=4.15<4.19.270 | ||
>=4.20<5.4.229 | ||
>=5.5<5.10.161 | ||
>=5.11<5.15.85 | ||
>=5.16<6.0.15 | ||
=37 | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45934 has a medium severity rating due to its potential impact on the integrity of the system.
To fix CVE-2022-45934, upgrade to a patched version of the Linux kernel, such as 5.10.223-1 or later.
CVE-2022-45934 affects various versions of the Linux kernel, specifically versions prior to 6.0.11.
CVE-2022-45934 can facilitate an integer overflow, potentially allowing for memory corruption.
Yes, CVE-2022-45934 involves an issue in the Bluetooth stack of the Linux kernel.