SB2022042146 - Denial of service in Linux kernel bluetooth
Published: April 21, 2022
Security Bulletin ID
SB2022042146
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-26878)
The vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak within the drivers/bluetooth/virtio_bt.c file in the Linux kernel. A local user can trigger leak memory and perform denial of service attack.
Remediation
Install update from vendor's website.
References
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.3
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1d0688421449718c6c5f46e458a378c9b530ba18
- https://lore.kernel.org/linux-bluetooth/1A203F5E-FB5E-430C-BEA3-86B191D69D58@holtmann.org/
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.17
- http://www.openwall.com/lists/oss-security/2022/03/11/1