CVE-2022-49138: Bluetooth: hci_event: Ignore multiple conn complete events
Published Feb 26, 2025
·Updated
Bluetooth: hcievent: Ignore multiple conn complete events
Affected Software
3 affected components
Linux Linux kernel
Linux Linux kernel<5.17.3
Microsoft cbl2 kernel 5.15.186.1-1
Event History
Feb 26, 2025
CVE Published
via MITRE·01:55 AM
Data Sourced
via MITRE·01:55 AM
DescriptionSeverity
Data Sourced
via NVD·07:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 25, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2022-49138?
CVE-2022-49138 is rated as having a medium severity level due to its potential impact on device memory management.
2
How do I fix CVE-2022-49138?
To fix CVE-2022-49138, upgrade your Linux kernel to version 5.17.4 or later, which includes the necessary patches.
3
What systems are affected by CVE-2022-49138?
CVE-2022-49138 affects the Linux kernel versions prior to 5.17.4.
4
What are the potential impacts of CVE-2022-49138?
The potential impacts of CVE-2022-49138 include erratic Bluetooth device behavior and possible memory leaks.
5
When was CVE-2022-49138 reported?
CVE-2022-49138 was reported and published in late 2022 as part of ongoing security updates for the Linux kernel.