CVE-2022-50233 (GCVE-0-2022-50233)
Vulnerability from cvelistv5
Published
2025-08-09 14:30
Modified
2026-08-05 08:57
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix using strlen with hdev->{dev_name,short_name} Both dev_name and short_name are not guaranteed to be NULL terminated so this instead use strnlen and then attempt to determine if the resulting string needs to be truncated or not.
Impacted products
Vendor Product Version
Linux Linux Version: 4c3dbb2c312c9fafbac30d98c523b8b1f3455d78
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/eir.c",
            "net/bluetooth/mgmt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "dd7b8cdde098cf9f7c8de409b5b7bbb98f97be80",
              "status": "affected",
              "version": "4c3dbb2c312c9fafbac30d98c523b8b1f3455d78",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/eir.c",
            "net/bluetooth/mgmt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.14"
            },
            {
              "lessThan": "4.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.0",
                  "versionStartIncluding": "4.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: eir: Fix using strlen with hdev-\u003e{dev_name,short_name}\n\nBoth dev_name and short_name are not guaranteed to be NULL terminated so\nthis instead use strnlen and then attempt to determine if the resulting\nstring needs to be truncated or not."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable strlen/eir_append paths are reached through the local HCI management socket (HCI_CHANNEL_CONTROL) via SET_LOCAL_NAME or READ_EXT_INFO, not by processing Bluetooth packets from a peer on the radio link.\nAC:L - After bluetoothd sets a typical adapter name of length \u003e= 10, hdev-\u003eshort_name is filled with 10 non-NUL bytes by memcpy, so strlen reliably reads out of bounds; an attacker can also set this state and trigger it deterministically with no race or attacker-uncontrollable condition.\nPR:L - READ_EXT_INFO is HCI_MGMT_UNTRUSTED so any local user can invoke append_eir_data_to_buf once the common non-NUL-terminated short_name state exists; on Android/desktop, apps or polkit-mediated users can also drive SET_LOCAL_NAME without init-namespace root.\nUI:N - The attacker opens their own HCI control socket and sends the mgmt command themselves; no separate victim action such as mounting a device or accepting a pairing request is required.\nS:U - Impact is host-kernel memory safety failure (OOB read/write and crash) within the same OS authority; this is not a VM escape, IOMMU/DMA bypass, or other cross-boundary compromise.\nC:H - strlen walks past short_name/dev_name into adjacent hci_dev fields, and eir_append_data copies that inflated u8 length into the READ_EXT_INFO response returned to userspace, disclosing more than a few bytes of kernel memory; stack/heap corruption from the same inflated length further enables read primitives.\nI:H - Inflated strlen results are passed into eir_append_data and written into undersized destinations (legacy scan_rsp HCI_MAX_AD_LENGTH=31, or the 512-byte mgmt ext-info stack buffer), producing out-of-bounds writes that can corrupt stack/heap and enable control-flow hijacking.\nA:H - The bugzilla reproducer hits fortify_panic/BUG in append_eir_data_to_buf on SET_LOCAL_NAME, and without FORTIFY the OOB read/write paths cause kernel oops/panic, fully denying availability."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:57:49.382Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dd7b8cdde098cf9f7c8de409b5b7bbb98f97be80"
        }
      ],
      "title": "Bluetooth: eir: Fix using strlen with hdev-\u003e{dev_name,short_name}",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-50233",
    "datePublished": "2025-08-09T14:30:51.639Z",
    "dateReserved": "2025-06-18T10:57:27.432Z",
    "dateUpdated": "2026-08-05T08:57:49.382Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…