CVE-2022-50233 is a vulnerability in the Linux kernel's Bluetooth Extended Inquiry Response (EIR) handling, specifically affecting the use of strlen with dev_name and short_name fields. These fields are not guaranteed to be NULL-terminated, leading to potential buffer over-reads. Rated as Medium severity (CVSS 5.5), this local vulnerability (AV:L) requires low privileges (PR:L) and could result in a denial of service (A:H). There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.14, < 6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.