CVE-2022-45934 is an integer-overflow flaw in the Linux kernel Bluetooth L2CAP configuration-request handler, l2cap_config_req() in net/bluetooth/l2cap_core.c. A local or Bluetooth-adjacent attacker can repeatedly send crafted L2CAP_CONF_REQ packets until the unsigned 8-bit chan->num_conf_rsp counter wraps after 255 responses, potentially disrupting Bluetooth communications or crashing the affected system. Red Hat rates the issue Moderate with a CVSS 3.1 score of 6.5; NVD and CVE.org list 7.8.
Upstream commit ae4569813a6e931258db627cdfe50dfb4f917d5d prevents the wraparound by limiting counter increments to L2CAP_CONF_MAX_CONF_RSP. Red Hat shipped fixes for affected RHEL 8 and RHEL 9 kernel packages in RHSA-2024:2394, RHSA-2024:2950, and RHSA-2024:3138, while RHEL 9 kernel-rt remained affected and RHEL 6/7 were outside support scope. Organizations unable to patch can reduce exposure by disabling Bluetooth through kernel-module blocklisting, hardware controls, or BIOS settings.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat fixed CVE-2022-45934 in the RHEL 8 kernel through RHSA-2024:3138 and in the RHEL 8 kernel-rt through RHSA-2024:2950.
Red Hat addressed CVE-2022-45934 for the Red Hat Enterprise Linux 9 kernel through advisory RHSA-2024:2394.
Sungwoo Kim authored a patch to prevent chan->num_conf_rsp from wrapping when repeated L2CAP_CONF_REQ packets are processed, by capping increments at L2CAP_CONF_MAX_CONF_RSP.
Luiz Augusto von Dentz committed ae4569813a6e931258db627cdfe50dfb4f917d5d, fixing the unsigned 8-bit overflow in the Bluetooth L2CAP configuration-response counter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.