Bugzilla – Bug 1204426
VUL-0: CVE-2022-3563: bluez: null dereference in mgmt-tester
Last modified: 2024-04-19 14:34:47 UTC
CVE-2022-3563 A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigned to this vulnerability. Upstream fix: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=e3c92f1f786f0b55440bd908b55894d0c792cf0e References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3563 https://www.cve.org/CVERecord?id=CVE-2022-3563 https://vuldb.com/?id.211086
Only SUSE:SLE-15-SP4:Update is affected. openSUSE:Factory already up-to-date
(In reply to Thomas Leroy from comment #1) > Only SUSE:SLE-15-SP4:Update is affected. > > openSUSE:Factory already up-to-date I have sent submitreq to SUSE:SLE-15-SP4:Update/bluez https://build.suse.de/request/show/288441
SUSE-SU-2023:0167-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1204426 CVE References: CVE-2022-3563 JIRA References: Sources used: openSUSE Leap 15.4 (src): bluez-5.62-150400.4.8.1 SUSE Linux Enterprise Workstation Extension 15-SP4 (src): bluez-5.62-150400.4.8.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src): bluez-5.62-150400.4.8.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): bluez-5.62-150400.4.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
(In reply to Joey Lee from comment #4) > (In reply to Thomas Leroy from comment #1) > > Only SUSE:SLE-15-SP4:Update is affected. > > > > openSUSE:Factory already up-to-date > > I have sent submitreq to SUSE:SLE-15-SP4:Update/bluez > > https://build.suse.de/request/show/288441 The patch be accepted. Reset assigner.
done