CVE-2022-0204
8.8
HIGH
CVSS 3.1
EPSS 0.05%
Description
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
How to fix CVE-2022-0204
To remediate CVE-2022-0204, upgrade the affected package to a fixed version below.
- Debian/bluez—upgrade to 5.55-3.1+deb11u2 or later
Is CVE-2022-0204 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 5.55-3.1+deb11u2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |