PT-2024-3414 · Linux+10 · Linux Kernel+10

Ying Hsu

·

Published

2024-02-28

·

Updated

2025-09-29

·

CVE-2024-26801

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to a potential use-after-free in the hci error reset() function when handling the HCI EV HARDWARE ERROR event. If the underlying BT controller is not responding, the GPIO reset mechanism would free the hci dev and lead to a use-after-free in hci error reset(). This could allow an attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is associated with the net/bluetooth/hci core.c module in the Linux kernel.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4211
ALSA-2024:4349
ALSA-2024:4352
ALSA-2025_16880
ALT-PU-2024-3574
BDU:2024-03686
CESA-2024_4211
CESA-2024_4352
CVE-2024-26801
DLA-3840-1
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_4211
INFSA-2024_4349
INFSA-2024_4352
OESA-2024-1617
OESA-2024-1618
OESA-2024-1622
OESA-2024-1647
OESA-2024-1648
OESA-2024-1681
RHSA-2024:4211
RHSA-2024:4349
RHSA-2024:4352
RHSA-2024:4447
RHSA-2024:4533
RHSA-2024:4554
RHSA-2024:4740
RHSA-2024_4211
RHSA-2024_4349
RHSA-2024_4352
RLSA-2024:4211
RLSA-2024:4349
RLSA-2024:4352
RXSA-2024:4211
RXSA-2024:4349
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:4367-1
SUSE-SU-2025:0035-1
USN-6774-1
USN-6777-1
USN-6777-2
USN-6777-3
USN-6777-4
USN-6778-1
USN-6820-1
USN-6820-2
USN-6821-1
USN-6821-2
USN-6821-3
USN-6821-4
USN-6828-1
USN-6831-1
USN-6867-1
USN-6871-1
USN-6892-1
USN-6919-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu