INFSA-2025:10670: kernel-rt security update

Information about definition

Identificator: INFSA-2025:10670

Type: security

Release date: 2025-07-25 10:21:09 UTC

Information about package

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Vulnerabilities description

  • CVE-2022-49111

    A vulnerability was found in the Linux kernel's Bluetooth subsystem in the hci_disconn_phylink_complete_evt() function. Improper cleanup and reference handling can lead to a connection object, hcon, being freed and then later accessed during a subsequent function call. This issue can lead to a use-after-free scenario, leading to system instability, memory corruption, and potential code execution.

  • CVE-2022-49136

    A vulnerability was found in the Linux kernel's Bluetooth subsystem in the hci_cmd_sync_queue() function. There was a missing check for whether the HCI_UNREGISTER flag had been set, meaning that commands were still sent even as the Bluetooth device was being unregistered. This issue could lead to a use-after-free scenario where the command is executed after the device structure is freed, potentially leading to a crash, arbitrary code execution, and system instability.

  • CVE-2022-49846

    In the Linux kernel, the following vulnerability has been resolved: udf: Fix a slab-out-of-bounds write bug in udf_find_entry().

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 7.0 no information
no information 7.0 no information
no information 7.1 no information
Critical, important, moderate, low

Updated packages