Red Hat released kernel and real-time kernel updates for supported Red Hat Enterprise Linux (RHEL) 8 and 9 systems to remediate CVE-2022-3619, a Bluetooth L2CAP memory-leak flaw in l2cap_recv_acldata within net/bluetooth/l2cap_core.c. An adjacent attacker could send malicious Bluetooth packets without privileges or user interaction and potentially exhaust memory or crash an affected host. Red Hat rated the issue moderate severity with a CVSS v3.1 score of 4.3 and classified it as CWE-401.
The fixes were included in RHEL 8 kernel version 4.18.0-477.10.1.el8_8 under RHSA-2023:2951 and the real-time kernel version 4.18.0-477.10.1.rt7.274.el8_8 under RHSA-2023:2736, alongside numerous other kernel security corrections affecting virtualization, networking, wireless, USB, and memory safety. Organizations should install the applicable kernel packages and reboot systems; where patching cannot occur promptly, disabling Bluetooth through module blocklisting, hardware controls, or BIOS settings reduces exposure.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:2951 for RHEL 8 kernel packages and RHSA-2023:2736 for RHEL 8 kernel-rt packages, both addressing CVE-2022-3619. Red Hat also closed Bug 2154235, its tracking record for the vulnerability.
Red Hat issued RHSA-2023:2458 for RHEL 9 kernel packages and RHSA-2023:2148 for RHEL 9 kernel-rt packages, addressing the Bluetooth L2CAP memory-leak flaw.
TEJ RATHI reported Red Hat Bug 2154235 for CVE-2022-3619, a memory leak in the Linux Bluetooth L2CAP l2cap_recv_acldata function.
Red Hat issued RHSA-2024:0724 to address CVE-2022-3619 for Red Hat Enterprise Linux 8.6 Extended Update Support and Red Hat Virtualization 4 for RHEL 8.
Fedora remediated CVE-2022-3619 through its Linux 6.0.8 stable kernel update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.