Home

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix crash on hci_create_cis_sync When attempting to connect multiple ISO sockets without using DEFER_SETUP may result in the following crash: BUG: KASAN: null-ptr-deref in hci_create_cis_sync+0x18b/0x2b0 Read of size 2 at addr 0000000000000036 by task kworker/u3:1/50 CPU: 0 PID: 50 Comm: kworker/u3:1 Not tainted 6.0.0-rc7-02243-gb84a13ff4eda #4373 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-1.fc36 04/01/2014 Workqueue: hci0 hci_cmd_sync_work Call Trace: <TASK> dump_stack_lvl+0x19/0x27 kasan_report+0xbc/0xf0 ? hci_create_cis_sync+0x18b/0x2b0 hci_create_cis_sync+0x18b/0x2b0 ? get_link_mode+0xd0/0xd0 ? __ww_mutex_lock_slowpath+0x10/0x10 ? mutex_lock+0xe0/0xe0 ? get_link_mode+0xd0/0xd0 hci_cmd_sync_work+0x111/0x190 process_one_work+0x427/0x650 worker_thread+0x87/0x750 ? process_one_work+0x650/0x650 kthread+0x14e/0x180 ? kthread_exit+0x50/0x50 ret_from_fork+0x22/0x30 </TASK>

PUBLISHED Reserved 2025-09-17 | Published 2025-10-01 | Updated 2025-10-01 | Assigner Linux

Product status

Default status
unaffected

26afbd826ee326e63a334c37fd45e82e50a615ec before a190cd9dc62d6ebeb679c1abe9dda4162dfefc84
affected

26afbd826ee326e63a334c37fd45e82e50a615ec before 09a3b0c9c7c6b10587fbb610b718014703cff341
affected

26afbd826ee326e63a334c37fd45e82e50a615ec before 50757a259ba78c4e938b5735e76ffec6cd0c942e
affected

Default status
affected

6.0
affected

Any version before 6.0
unaffected

6.0.16
unaffected

6.1.2
unaffected

6.2
unaffected

References

git.kernel.org/...c/a190cd9dc62d6ebeb679c1abe9dda4162dfefc84

git.kernel.org/...c/09a3b0c9c7c6b10587fbb610b718014703cff341

git.kernel.org/...c/50757a259ba78c4e938b5735e76ffec6cd0c942e

cve.org (CVE-2022-50447)

nvd.nist.gov (CVE-2022-50447)

Download JSON