CVE-2022-3564 is a use-after-free flaw in the Linux kernel Bluetooth L2CAP implementation, in l2cap_reassemble_sdu() within net/bluetooth/l2cap_core.c. A local user or an attacker able to establish a Bluetooth connection can use two malicious L2CAP packet flows to trigger a race condition, potentially crashing the host or escalating privileges. Red Hat rates the issue CVSS 7.1; exploitation requires low privileges and winning a narrow timing window, and no practical exploit was known.
The upstream fix is available in commit 89f9f3cb86b1c63badaf392a83dd661d56cc50b1, with Fedora remediating it in Linux 6.0.8 stable updates and Red Hat issuing fixes for affected RHEL 7, 8, and 9 channels, including RHSA-2023:4150 and RHSA-2023:4151. Organizations unable to patch should disable Bluetooth at the hardware or BIOS level, or block Bluetooth kernel modules such as bnep, bluetooth, and btusb and disable the Bluetooth service.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:4150 for RHEL 7 kernel-rt and RHSA-2023:4151 for the RHEL 7 kernel, addressing the L2CAP Bluetooth use-after-free flaw CVE-2022-3564.
Red Hat released RHSA-2023:4020 and RHSA-2023:4021, addressing CVE-2022-3564 in RHEL 7.4 and RHEL 7.6 Advanced Update Support kernels.
Red Hat issued RHSA-2023:3431, an Important security update for the kpatch-patch live kernel module on RHEL 8.6 EUS, ELL, AUS, TUS, and SAP Update Services variants. The live patch fixes the Bluetooth L2CAP use-after-free flaw CVE-2022-3564 and the procfs stack-overflow flaw CVE-2022-4378.
Red Hat released RHSA-2023:3277 for the RHEL 7.7 Advanced Update Support kernel and RHSA-2023:3278 for the RHEL 7.7 SAP Solutions kpatch-patch package.
Red Hat released RHSA-2023:2736, fixing CVE-2022-3564 in the Red Hat Enterprise Linux 8 kernel-rt package.
Red Hat issued RHSA-2023:1435, updating the kpatch-patch live kernel module for RHEL 9.0 Extended Update Support and SAP Update Services. The advisory fixes CVE-2022-3564 along with four other Linux-kernel vulnerabilities without requiring a conventional kernel reboot.
Red Hat issued RHSA-2023:1251, an Important security advisory updating the kpatch-patch live kernel module for RHEL 8.4 EUS and associated channels. The live patch remediates CVE-2022-3564 and CVE-2022-4378 on x86_64 and ppc64le systems.
Red Hat issued RHSA-2023:1221 for the RHEL 8.4 kernel in Extended Update Support and related channels. The update to kernel-4.18.0-305.82.1.el8_4 fixes CVE-2022-3564, CVE-2022-4378, and CVE-2022-4269; affected systems must be rebooted for the fixes to take effect.
Red Hat released RHSA-2023:0951 to fix CVE-2022-49910, a Bluetooth L2CAP use-after-free vulnerability, in the RHEL 9 kernel. The flaw involves a race between packet reassembly and socket receive processing that can leave code accessing a freed SKB control buffer.
Red Hat issued RHSA-2023:0856 for RHEL 8.1 Update Services for SAP Solutions, updating kernel packages to version 4.18.0-147.80.1.el8_1. The update fixes CVE-2022-2964, CVE-2022-3564, and CVE-2022-4378 on x86_64 and Power LE ppc64le systems; administrators must reboot after installation.
Red Hat issued RHSA-2023:0858 for the RHEL 8.1 Update Services for SAP Solutions kpatch-patch module. The live patch remediates CVE-2022-3564, CVE-2022-2964, and CVE-2022-4378 for x86_64 and Power LE ppc64le deployments.
Red Hat released RHSA-2023:4215, providing a kpatch-patch fix for CVE-2022-3564 on Red Hat Enterprise Linux 7.
Red Hat closed its CVE-2023-0266 case after delivering errata for the ALSA snd_ctl_elem_read use-after-free vulnerability, including fixes across affected RHEL 8 and RHEL 9 streams and Red Hat Virtualization 4 for RHEL 8. The flaw could allow a privileged local attacker to leak kernel information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
19 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.