PT-2024-10131 · Linux+4 · Linux Kernel+4

Published

2024-12-12

·

Updated

2025-10-03

·

CVE-2024-56653

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.74
Description The issue is related to a use-after-free vulnerability in the btmtk process coredump() function in the Linux kernel's Bluetooth module. This vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. The vulnerability occurs when hci devcd append may lead to the release of the skb, making it inaccessible once it is called. The estimated number of potentially affected devices worldwide is not specified.
Technical details about exploitation include:
  • The vulnerable function is btmtk process coredump().
  • The hci devcd append function may cause the release of the skb.
  • To fix the issue, it is suggested to check if hci devcd complete needs to be called before hci devcd append, and to check data->cd info.cnt >= MTK COREDUMP NUM instead of data->cd info.cnt > MTK COREDUMP NUM.
Recommendations
  • Update to Linux kernel version 6.6.74 or later to resolve the issue.
  • As a temporary workaround, consider restricting access to the vulnerable Bluetooth module until a patch is available.
  • At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17881
ALT-PU-2025-12647
ALT-PU-2025-3496
AZL-54875
BDU:2025-00388
CVE-2024-56653
INFSA-2025_6966
LSN-0112-1
MGASA-2025-0030
MGASA-2025-0032
OESA-2025-1093
OESA-2025-1097
RHSA-2025:6966
RHSA-2025_6966
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7492-1
USN-7492-2
USN-7500-1
USN-7500-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Hat
Ubuntu