PT-2024-26808 · Linux+6 · Linux Kernel+6
Syzbot
·
Published
2024-04-05
·
Updated
2025-09-29
·
CVE-2024-35967
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the Bluetooth SCO (Synchronous Connection-Oriented) protocol in the Linux kernel. The
sco sock setsockopt() function is copying data without checking the user input length, leading to a slab-out-of-bounds error. This error occurs in the copy from sockptr offset and copy from sockptr functions, which are part of the include/linux/sockptr.h file. The vulnerability is also associated with the sco sock setsockopt+0xc0b/0xf90 function in the net/bluetooth/sco.c file. A read of size 4 at address ffff88805f7b15a3 by task syz-executor.5/12578 has been reported.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu