{"id":"DEBIAN-CVE-2022-50447","details":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_conn: Fix crash on hci_create_cis_sync  When attempting to connect multiple ISO sockets without using DEFER_SETUP may result in the following crash:  BUG: KASAN: null-ptr-deref in hci_create_cis_sync+0x18b/0x2b0 Read of size 2 at addr 0000000000000036 by task kworker/u3:1/50  CPU: 0 PID: 50 Comm: kworker/u3:1 Not tainted 6.0.0-rc7-02243-gb84a13ff4eda #4373 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-1.fc36 04/01/2014 Workqueue: hci0 hci_cmd_sync_work Call Trace:  \u003cTASK\u003e  dump_stack_lvl+0x19/0x27  kasan_report+0xbc/0xf0  ? hci_create_cis_sync+0x18b/0x2b0  hci_create_cis_sync+0x18b/0x2b0  ? get_link_mode+0xd0/0xd0  ? __ww_mutex_lock_slowpath+0x10/0x10  ? mutex_lock+0xe0/0xe0  ? get_link_mode+0xd0/0xd0  hci_cmd_sync_work+0x111/0x190  process_one_work+0x427/0x650  worker_thread+0x87/0x750  ? process_one_work+0x650/0x650  kthread+0x14e/0x180  ? kthread_exit+0x50/0x50  ret_from_fork+0x22/0x30  \u003c/TASK\u003e","modified":"2026-09-01T20:05:00.111966777Z","published":"2025-10-01T12:15:37.177Z","upstream":["CVE-2022-50447"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50447"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50447.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50447.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50447.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}