PT-2024-34088 · Linux+8 · Linux Kernel+8

Sungwoo Kim

·

Published

2024-10-29

·

Updated

2025-10-03

·

CVE-2024-50255

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.6.61
Description: A null pointer dereference issue has been identified in the Linux kernel's Bluetooth functionality, specifically in the hci read supported codecs function. This issue arises when the hci cmd sync sk() function returns NULL for unknown opcodes, leading to a null pointer dereference in the cmd sync function for HCI OP READ LOCAL CODECS. The problem occurs because there is no hci cc entry for HCI OP READ LOCAL CODECS, causing the function to assume a status value of skb->data[0]. This results in a null pointer dereference in the range [0x0000000000000070-0x0000000000000077].
Recommendations: To resolve this issue, update the Linux kernel to version 6.6.61 or later. As a temporary workaround, consider disabling the Bluetooth functionality until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:11486
ALSA-2024_11486
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-16040
ALT-PU-2024-17211
ALT-PU-2024-17891
ALT-PU-2025-12647
AZL-53298
BDU:2025-04149
CVE-2024-50255
DLA-4008-1
DSA-5818-1
INFSA-2024_11486
MGASA-2024-0368
MGASA-2024-0369
OESA-2024-2492
OPENSUSE-SU-2024:14500-1
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4376-1
OPENSUSE-SU-2025:14705-1
RHSA-2024:11486
RHSA-2024_11486
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu