Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-344917
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 07:58
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T07:58:41.839072+00:00",
"id": "EUVD-2026-344917"
}
CVE-2022-50419 (GCVE-0-2022-50419)
Vulnerability from cvelistv5 – Published: 2025-09-18 16:04 – Updated: 2026-08-05 08:58
VLAI
EPSS
VEX
Title
Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times
device_add shall not be called multiple times as stated in its
documentation:
'Do not call this routine or device_register() more than once for
any device structure'
Syzkaller reports a bug as follows [1]:
------------[ cut here ]------------
kernel BUG at lib/list_debug.c:33!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
[...]
Call Trace:
<TASK>
__list_add include/linux/list.h:69 [inline]
list_add_tail include/linux/list.h:102 [inline]
kobj_kset_join lib/kobject.c:164 [inline]
kobject_add_internal+0x18f/0x8f0 lib/kobject.c:214
kobject_add_varg lib/kobject.c:358 [inline]
kobject_add+0x150/0x1c0 lib/kobject.c:410
device_add+0x368/0x1e90 drivers/base/core.c:3452
hci_conn_add_sysfs+0x9b/0x1b0 net/bluetooth/hci_sysfs.c:53
hci_le_cis_estabilished_evt+0x57c/0xae0 net/bluetooth/hci_event.c:6799
hci_le_meta_evt+0x2b8/0x510 net/bluetooth/hci_event.c:7110
hci_event_func net/bluetooth/hci_event.c:7440 [inline]
hci_event_packet+0x63d/0xfd0 net/bluetooth/hci_event.c:7495
hci_rx_work+0xae7/0x1230 net/bluetooth/hci_core.c:4007
process_one_work+0x991/0x1610 kernel/workqueue.c:2289
worker_thread+0x665/0x1080 kernel/workqueue.c:2436
kthread+0x2e4/0x3a0 kernel/kthread.c:376
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306
</TASK>
Severity
8.8 (High)
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-01-14 19:11 UTC
CWE
- CWE-415 - Double Free
Assigner
References
9 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
b219e3ac66183fc9771b94af931fb5fd41d586ec , < 4bcefec3636208b4c97536b26014d5935d5c10a0
(git)
Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < 6144423712d570247b8ca26e50a277c30dd13702 (git) Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < 671fee73e08ff415d36a7c16bdf238927df83884 (git) Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < 6e85d2ad958c6f034b1b158d904019869dbb3c81 (git) Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < 7b674dce4162bb46d396586e30e4653427023875 (git) Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < 3423a50fa018e88aed4c900d59c3c8334d8ad583 (git) Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < ef055094df4c10b73cfe67c8d43f9de1fb608a8b (git) Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < 1b6c89571f453101251201f0fad1c26f7256e937 (git) Affected: b219e3ac66183fc9771b94af931fb5fd41d586ec , < 448a496f760664d3e2e79466aa1787e6abc922b5 (git) |
|
| Linux | Linux |
Affected:
2.6.19
Unaffected: 0 , < 2.6.19 (semver) Unaffected: 4.9.331 , ≤ 4.9.* (semver) Unaffected: 4.14.296 , ≤ 4.14.* (semver) Unaffected: 4.19.262 , ≤ 4.19.* (semver) Unaffected: 5.4.220 , ≤ 5.4.* (semver) Unaffected: 5.10.150 , ≤ 5.10.* (semver) Unaffected: 5.15.75 , ≤ 5.15.* (semver) Unaffected: 5.19.17 , ≤ 5.19.* (semver) Unaffected: 6.0.3 , ≤ 6.0.* (semver) Unaffected: 6.1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2022-50419",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-14T19:11:20.804878Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-415",
"description": "CWE-415 Double Free",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-01-14T19:13:10.240Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sysfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4bcefec3636208b4c97536b26014d5935d5c10a0",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "6144423712d570247b8ca26e50a277c30dd13702",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "671fee73e08ff415d36a7c16bdf238927df83884",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "6e85d2ad958c6f034b1b158d904019869dbb3c81",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "7b674dce4162bb46d396586e30e4653427023875",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "3423a50fa018e88aed4c900d59c3c8334d8ad583",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "ef055094df4c10b73cfe67c8d43f9de1fb608a8b",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "1b6c89571f453101251201f0fad1c26f7256e937",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
},
{
"lessThan": "448a496f760664d3e2e79466aa1787e6abc922b5",
"status": "affected",
"version": "b219e3ac66183fc9771b94af931fb5fd41d586ec",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/hci_sysfs.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"lessThan": "2.6.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.9.*",
"status": "unaffected",
"version": "4.9.331",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.14.*",
"status": "unaffected",
"version": "4.14.296",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.19.*",
"status": "unaffected",
"version": "4.19.262",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.150",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.19.*",
"status": "unaffected",
"version": "5.19.17",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.0.*",
"status": "unaffected",
"version": "6.0.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.9.331",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.14.296",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.19.262",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.220",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.150",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.75",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.19.17",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.3",
"versionStartIncluding": "2.6.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1",
"versionStartIncluding": "2.6.19",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sysfs: Fix attempting to call device_add multiple times\n\ndevice_add shall not be called multiple times as stated in its\ndocumentation:\n\n \u0027Do not call this routine or device_register() more than once for\n any device structure\u0027\n\nSyzkaller reports a bug as follows [1]:\n------------[ cut here ]------------\nkernel BUG at lib/list_debug.c:33!\ninvalid opcode: 0000 [#1] PREEMPT SMP KASAN\n[...]\nCall Trace:\n \u003cTASK\u003e\n __list_add include/linux/list.h:69 [inline]\n list_add_tail include/linux/list.h:102 [inline]\n kobj_kset_join lib/kobject.c:164 [inline]\n kobject_add_internal+0x18f/0x8f0 lib/kobject.c:214\n kobject_add_varg lib/kobject.c:358 [inline]\n kobject_add+0x150/0x1c0 lib/kobject.c:410\n device_add+0x368/0x1e90 drivers/base/core.c:3452\n hci_conn_add_sysfs+0x9b/0x1b0 net/bluetooth/hci_sysfs.c:53\n hci_le_cis_estabilished_evt+0x57c/0xae0 net/bluetooth/hci_event.c:6799\n hci_le_meta_evt+0x2b8/0x510 net/bluetooth/hci_event.c:7110\n hci_event_func net/bluetooth/hci_event.c:7440 [inline]\n hci_event_packet+0x63d/0xfd0 net/bluetooth/hci_event.c:7495\n hci_rx_work+0xae7/0x1230 net/bluetooth/hci_core.c:4007\n process_one_work+0x991/0x1610 kernel/workqueue.c:2289\n worker_thread+0x665/0x1080 kernel/workqueue.c:2436\n kthread+0x2e4/0x3a0 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306\n \u003c/TASK\u003e"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable path is Bluetooth HCI event handling (hci_le_cis_estabilished_evt \u2192 hci_conn_add_sysfs) reached when establishing LE Audio/CIS or related links with a nearby Bluetooth peer/controller, so exploitation requires adjacency rather than local shell or routable network access.\nAC:L - An attacker who can drive the HCI event sequence (malicious/buggy controller, or duplicate CIS Established / handle-colliding events) triggers the double device_add reliably; no race or attacker-uncontrollable timing is required.\nPR:N - A nearby Bluetooth peer needs no account or capability on the victim host; connection acceptance is performed by the victim\u2019s normal Bluetooth/LE Audio stack, not by attacker-held OS privileges.\nUI:N - Once Bluetooth is enabled and reachable for CIS/LE connections (common on phones and audio devices), the kernel processes the HCI events asynchronously without further victim action.\nS:U - Impact stays within the host kernel Bluetooth/driver-model authority; this is not a VM escape, IOMMU bypass, or other cross-scope boundary violation.\nC:H - Double device_add corrupts the kobject kset linked list; without list-debug BUG paths this is kernel memory corruption that can be leveraged for arbitrary read primitives, so confidentiality is High.\nI:H - The same list corruption yields classic unlink/write primitives against kernel list pointers, enabling integrity compromise and potential code execution under the required higher-severity rule.\nA:H - With list debugging the double add hits a kernel BUG/oops; without it, corrupted kset lists still cause crashes or hangs when devices are walked or removed, so availability is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T08:58:43.597Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4bcefec3636208b4c97536b26014d5935d5c10a0"
},
{
"url": "https://git.kernel.org/stable/c/6144423712d570247b8ca26e50a277c30dd13702"
},
{
"url": "https://git.kernel.org/stable/c/671fee73e08ff415d36a7c16bdf238927df83884"
},
{
"url": "https://git.kernel.org/stable/c/6e85d2ad958c6f034b1b158d904019869dbb3c81"
},
{
"url": "https://git.kernel.org/stable/c/7b674dce4162bb46d396586e30e4653427023875"
},
{
"url": "https://git.kernel.org/stable/c/3423a50fa018e88aed4c900d59c3c8334d8ad583"
},
{
"url": "https://git.kernel.org/stable/c/ef055094df4c10b73cfe67c8d43f9de1fb608a8b"
},
{
"url": "https://git.kernel.org/stable/c/1b6c89571f453101251201f0fad1c26f7256e937"
},
{
"url": "https://git.kernel.org/stable/c/448a496f760664d3e2e79466aa1787e6abc922b5"
}
],
"title": "Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2022-50419",
"datePublished": "2025-09-18T16:04:02.152Z",
"dateReserved": "2025-09-17T14:53:07.003Z",
"dateUpdated": "2026-08-05T08:58:43.597Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…