CVE-2022-49754
Published: Mar 27, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() Smatch Warning: net/bluetooth/mgmt_util.c:375 mgmt_mesh_add() error: __memcpy() 'mesh_tx->param' too small (48 vs 50) Analysis: 'mesh_tx->param' is array of size 48. This is the destination. u8 param[sizeof(struct mgmt_cp_mesh_send) + 29]; // 19 + 29 = 48. But in the caller 'mesh_send' we reject only when len > 50. len > (MGMT_MESH_SEND_SIZE + 31) // 19 + 31 = 50.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected b338d91703fae6f6afd67f3f75caa3b8f36ddef3 - < ed818fd8c531abf561b379995ee7cc4c68029464affected b338d91703fae6f6afd67f3f75caa3b8f36ddef3 - < 2185e0fdbb2137f22a9dd9fcbf6481400d56299b |
Linux | Linux | affected 6.1unaffected 0 - < 6.1unaffected 6.1.9 - <= 6.1.*unaffected 6.2 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now