PT-2024-35655 · Linux+7 · Linux Kernel+7
Syzbot
·
Published
2024-11-26
·
Updated
2026-02-21
·
CVE-2024-53208
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.11.0-rc6-syzkaller-01155-gf723224742fc
Description
A slab-use-after-free read vulnerability has been identified in the Linux kernel's Bluetooth MGMT component, specifically in the
set powered sync function. This issue can cause a crash when a task attempts to read from a freed memory location. The vulnerability is related to the hci cmd sync work function and the mgmt pending new function. The estimated number of potentially affected devices is not specified.Recommendations
To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu