CVE-2022-42896
Info Leak in l2cap_core in the Linux Kernel
- Published
- Nov 23, 2022
- Updated
- Apr 21, 2025
- Assigning CNA
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 80.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url
Sources
2- linux-4.19.72_CVE-2022-42896Research
Linux kernel source tree modified to address CVE-2022-42896, providing a reference for vulnerability analysis and exploitation research.
Linux kernel source tree modified to demonstrate or patch CVE-2022-42896, a use-after-free vulnerability in the netfilter subsystem, for analysis and educational purposes.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.