Severity
7.1
High severity
Details
- CVSS score
- 7.1
- CVSS vector
- CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE ID
Overview
About vulnerability
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Details
- Affected product:
- AlmaLinux 9.2 ESU , Amazon Linux 2 ELS , CentOS 6 ELS , CentOS 7 ELS , CentOS 8.4 ELS , CentOS 8.5 ELS , CentOS Stream 8 ELS , CloudLinux 6 ELS , CloudLinux 7 ELS , Debian 10 ELS , Oracle Linux 6 ELS , Oracle Linux 7 ELS , RHEL 7 ELS , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS
- Affected packages:
- kernel @ 2.6.32 (+16 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 8 backports | Released |
24 kernels
|
| Debian 9 | Released |
52 kernels
|
| Endurance 6 elrepo | Released |
1 kernel
|
| Endurance 7 eig 3.10 | Released |
2 kernels
|
| Proofpoint | Ready For Release | — |
| Proxmox VE 5 | Released |
47 kernels
|
| Ubuntu 14.04 HWE | Released |
66 kernels
|
| Ubuntu 16.04 | Released |
110 kernels
|
| Ubuntu 16.04 AWS | Released |
78 kernels
|
| Ubuntu 16.04 AWS ESM | Ready For Release | — |
| Ubuntu 16.04 AWS HWE | Released |
43 kernels
|
| Ubuntu 16.04 AWS HWE ESM | Ready For Release | — |
| Ubuntu 16.04 Azure | Released |
59 kernels
|
| Ubuntu 16.04 Azure ESM | Ready For Release | — |
| Ubuntu 16.04 GCP | Released |
37 kernels
|
| Ubuntu 16.04 GCP ESM | Ready For Release | — |
| Ubuntu 16.04 HWE | Released |
58 kernels
|
| Ubuntu 16.04 HWE ESM | Ready For Release | — |
| Ubuntu 18.04 GCP | Released |
27 kernels
|
| Ubuntu 20.04 AWS Hirsute | Released |
8 kernels
|
| Ubuntu 20.04 HWE Hirsute | Released |
10 kernels
|