PT-2024-33909 · Linux+7 · Linux Kernel+7
Aaron Thompson
+1
·
Published
2024-10-28
·
Updated
2025-10-03
·
CVE-2024-50077
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to the fixed version
Description:
The issue arises when
bt debugfs is not created successfully due to either CONFIG DEBUG FS or CONFIG DEBUG FS ALLOW ALL being unset. This leads to iso init() returning early without setting iso inited to true, resulting in duplicate calls to proto register(), bt sock register(), etc. when iso init() is called subsequently. With CONFIG LIST HARDENED and CONFIG BUG ON DATA CORRUPTION enabled, the duplicate call to proto register() triggers a bug. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.Recommendations:
To resolve the issue, update the Linux kernel to a version that includes the fix for this problem.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu