The vendor explicitly identifies these products as affected by this CVE.
- kernel as a component of Red Hat Enterprise Linux 6
- kernel-abi-whitelists as a component of Red Hat Enterprise Linux 6
- kernel-bootwrapper as a component of Red Hat Enterprise Linux 6
- kernel-debug as a component of Red Hat Enterprise Linux 6
- kernel-debug-devel as a component of Red Hat Enterprise Linux 6
- kernel-devel as a component of Red Hat Enterprise Linux 6
- kernel-doc as a component of Red Hat Enterprise Linux 6
- kernel-firmware as a component of Red Hat Enterprise Linux 6
- kernel-headers as a component of Red Hat Enterprise Linux 6
- kernel-kdump as a component of Red Hat Enterprise Linux 6
- kernel-kdump-devel as a component of Red Hat Enterprise Linux 6
- kernel.src as a component of Red Hat Enterprise Linux 6
- Summary
- CVE-2022-49138 is a vulnerability in the Linux kernel's Bluetooth subsystem, specifically within the handling of Host Controller Interface (HCI) events. The issue arises when the kernel receives multiple "connection complete" events for the same Bluetooth connection handle. In such cases, the kernel erroneously registers the same device multiple times, leading to memory corruption. This flaw could potentially be exploited to cause system instability or other unintended behaviors.
- Remediation
- Affected
