INFSA-2025:10669: kernel security update
Information about definition
Identificator: INFSA-2025:10669
Type: security
Release date: 2025-07-25 10:35:53 UTC
Information about package
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Vulnerabilities description
- CVE-2022-49111
A vulnerability was found in the Linux kernel's Bluetooth subsystem in the hci_disconn_phylink_complete_evt() function. Improper cleanup and reference handling can lead to a connection object, hcon, being freed and then later accessed during a subsequent function call. This issue can lead to a use-after-free scenario, leading to system instability, memory corruption, and potential code execution.
- CVE-2022-49136
A vulnerability was found in the Linux kernel's Bluetooth subsystem in the hci_cmd_sync_queue() function. There was a missing check for whether the HCI_UNREGISTER flag had been set, meaning that commands were still sent even as the Bluetooth device was being unregistered. This issue could lead to a use-after-free scenario where the command is executed after the device structure is freed, potentially leading to a crash, arbitrary code execution, and system instability.
- CVE-2022-49846
In the Linux kernel, the following vulnerability has been resolved: udf: Fix a slab-out-of-bounds write bug in udf_find_entry().
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2022-49111
|
no information | 7.0 | no information |
NIST — CVE-2022-49136
|
no information | 7.0 | no information |
NIST — CVE-2022-49846
|
no information | 7.1 | no information |
Updated packages