CVE-2024-42133
7.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Ignore too large handle values in BIG
hci_le_big_sync_established_evt is necessary to filter out cases where the handle value is belonging to ida id range, otherwise ida will be erroneously released in hci_conn_cleanup.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | f7e83f2278f06b577e3c92ea2f4e8e8c6fc72a8f < a06a8cc80fa203fde828a8429583f7e4fe27eca4 | affected |
| Linux | Linux | 84cb0143fb8a03bf941c7aaedd56c938c99dafad < 38263088b845abeeeb98dda5b87c0de3063b6dbb | affected |
| Linux | Linux | 181a42edddf51d5d9697ecdf365d72ebeab5afb0 < dad0003ccc68457baf005a6ed75b4d321463fe3d | affected |
| Linux | Linux | 181a42edddf51d5d9697ecdf365d72ebeab5afb0 < 015d79c96d62cd8a4a359fcf5be40d58088c936b | affected |
| Linux | Linux | e9f708beada55426c8d678e2f46af659eb5bf4f0 | affected |
| Linux | Linux | 6.6.2 < 6.6.39 | affected |
| Linux | Linux | 6.5.12 < 6.6 | affected |
| Linux | Linux | 6.7 | affected |
| Linux | Linux | 0 < 6.7 | unaffected |
| Linux | Linux | 6.6.39 <= 6.6.* | unaffected |
| Linux | Linux | 6.9.9 <= 6.9.* | unaffected |
| Linux | Linux | 6.10 <= * | unaffected |
Weaknesses
ADP Enrichment
CVE Program Container
Additional References
- https://git.kernel.org/stable/c/38263088b845abeeeb98dda5b87c0de3063b6dbb
- https://git.kernel.org/stable/c/dad0003ccc68457baf005a6ed75b4d321463fe3d
- https://git.kernel.org/stable/c/015d79c96d62cd8a4a359fcf5be40d58088c936b
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://git.kernel.org/stable/c/a06a8cc80fa203fde828a8429583f7e4fe27eca4
- https://git.kernel.org/stable/c/38263088b845abeeeb98dda5b87c0de3063b6dbb
- https://git.kernel.org/stable/c/dad0003ccc68457baf005a6ed75b4d321463fe3d
- https://git.kernel.org/stable/c/015d79c96d62cd8a4a359fcf5be40d58088c936b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.