-
Security Vulnerability
-
Resolution: Fixed
-
Normal
-
None
-
None
-
None
-
security debian kernel
[medium] CVE-2022-42895:
There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely.
- https://nvd.nist.gov/vuln/detail/CVE-2022-42895
- https://github.com/google/security-research/security/advisories/GHSA-vccx-8h74-2357
- https://security-tracker.debian.org/tracker/CVE-2022-42895
[high] CVE-2022-42896:
There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth.