CVE-2022-0204
Summary
| CVE | CVE-2022-0204 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:44:55 UTC |
| Updated | 2026-04-15 21:17:03 UTC |
| Description | A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.000500000 probability, percentile 0.152360000 (date 2026-04-15)
Problem Types: CWE-119 | CWE-190 | CWE-119 CWE-119
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 5.8 | AV:A/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:A/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bluez | Bluez | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| shared/gatt-server: Fix heap overflow when appending prepare writes · bluez/bluez@591c546 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch, Third Party Advisory |
| [SECURITY] [DLA 3157-1] bluez security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| lists.debian.org/debian-lts-announce/2024/09/msg00022.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| BlueZ: Multiple Vulnerabilities (GLSA 202209-16) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Heap overflow vulnerability in the implementation of the gatt protocol · Advisory · bluez/bluez · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Third Party Advisory |
| 2039807 – (CVE-2022-0204) CVE-2022-0204 bluez: heap-based buffer overflow in the implementation of the gatt protocol | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181160 Debian Security Update for bluez (DLA 3157-1)
- 183630 Debian Security Update for bluez (CVE-2022-0204)
- 198657 Ubuntu Security Notification for BlueZ Vulnerability (USN-5275-1)
- 355441 Amazon Linux Security Advisory for bluez : ALAS2023-2023-212
- 355701 Amazon Linux Security Advisory for bluez : ALAS2-2023-2167
- 671575 EulerOS Security Update for bluez (EulerOS-SA-2022-1557)
- 671653 EulerOS Security Update for bluez (EulerOS-SA-2022-1707)
- 671733 EulerOS Security Update for bluez (EulerOS-SA-2022-1784)
- 671735 EulerOS Security Update for bluez (EulerOS-SA-2022-1801)
- 671791 EulerOS Security Update for bluez (EulerOS-SA-2022-1858)
- 671795 EulerOS Security Update for bluez (EulerOS-SA-2022-1834)
- 671848 EulerOS Security Update for bluez (EulerOS-SA-2022-1882)
- 710631 Gentoo Linux BlueZ Multiple Vulnerabilities (GLSA 202209-16)
- 752482 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2022:2837-1)
- 752503 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2022:2883-1)
- 752524 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2022:2948-1)
- 752578 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2022:3247-1)