In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().
Update Linux/Linux to 1b1c0da227bf63479bac9982fc8d12df9aaea0fb if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <1b1c0da227bf63479bac9982fc8d12df9aaea0fb || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <85426e97dc72f2088ba6d27e74cd58c3fbd43e31 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <0c17c8832562b2aac288e89cefd0f46074f54bcb || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <5105f3e6b2df619c635b5f6a49fac131a36c7952 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <c88c185ae0a1067823661b220aeea613df2c127b || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <1810e42ff6716f320c7269d5850eca48b07b7427 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <a2dcf1a61d056aef15b63c6eae9441344d624389 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <2ff1a41a912de8517b4482e946dd951b7d80edbf |
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().
Update Linux/Linux to 1b1c0da227bf63479bac9982fc8d12df9aaea0fb if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <1b1c0da227bf63479bac9982fc8d12df9aaea0fb || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <85426e97dc72f2088ba6d27e74cd58c3fbd43e31 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <0c17c8832562b2aac288e89cefd0f46074f54bcb || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <5105f3e6b2df619c635b5f6a49fac131a36c7952 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <c88c185ae0a1067823661b220aeea613df2c127b || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <1810e42ff6716f320c7269d5850eca48b07b7427 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <a2dcf1a61d056aef15b63c6eae9441344d624389 || >=89bc500e41fc5b48e0573e6b0d927fc97b8951dc <2ff1a41a912de8517b4482e946dd951b7d80edbf |
| 1b1c0da227bf63479bac9982fc8d12df9aaea0fb, 85426e97dc72f2088ba6d27e74cd58c3fbd43e31, 0c17c8832562b2aac288e89cefd0f46074f54bcb, 5105f3e6b2df619c635b5f6a49fac131a36c7952, c88c185ae0a1067823661b220aeea613df2c127b, 1810e42ff6716f320c7269d5850eca48b07b7427, a2dcf1a61d056aef15b63c6eae9441344d624389, 2ff1a41a912de8517b4482e946dd951b7d80edbf |
| Linux/Linuxgeneric | 3.1 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 1b1c0da227bf63479bac9982fc8d12df9aaea0fb, 85426e97dc72f2088ba6d27e74cd58c3fbd43e31, 0c17c8832562b2aac288e89cefd0f46074f54bcb, 5105f3e6b2df619c635b5f6a49fac131a36c7952, c88c185ae0a1067823661b220aeea613df2c127b, 1810e42ff6716f320c7269d5850eca48b07b7427, a2dcf1a61d056aef15b63c6eae9441344d624389, 2ff1a41a912de8517b4482e946dd951b7d80edbf |
| Linux/Linuxgeneric | 3.1 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard