Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
hci_conn_params_lookup requires hdev->lock be held, otherwise the list iteration or param access is not safe.
Hold hdev->lock for params lookups in hci_sync.
Details
- Affected product:
- Debian 10 ELS
- Affected packages:
- linux @ 4.19.0