PT-2024-3619 · Linux+9 · Linux Kernel+9

Published

2024-05-03

·

Updated

2025-09-29

·

CVE-2024-27399

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.9.0-rc5-00356-g78c0094a146b
Description: The issue is related to a null pointer dereference bug in the Linux kernel's Bluetooth subsystem, specifically in the l2cap chan timeout function. This bug occurs due to a race condition between l2cap chan timeout and l2cap chan del, where the chan->conn is set to null when the channel is deleted, but can still be dereferenced in the mutex lock of l2cap chan timeout. The KASAN report triggered by the Proof of Concept (POC) shows the null pointer dereference error.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the null pointer dereference bug in the l2cap chan timeout function. As a temporary workaround, consider disabling the Bluetooth functionality until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:10281
ALSA-2024:11486
ALSA-2024_11486
ALSA-2025_16880
BDU:2024-03936
CESA-2024_10281
CVE-2024-27399
DLA-3840-1
DLA-3843-1
DSA-5703-1
INFSA-2024_10281
INFSA-2024_11486
OESA-2024-1692
OESA-2024-1694
OESA-2024-1706
RHSA-2024:10281
RHSA-2024:10771
RHSA-2024:10772
RHSA-2024:10773
RHSA-2024:11486
RHSA-2024:6993
RHSA-2024_10281
RHSA-2024_11486
RLSA-2024:10281
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6949-1
USN-6949-2
USN-6950-1
USN-6950-2
USN-6950-3
USN-6950-4
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6952-1
USN-6952-2
USN-6953-1
USN-6955-1
USN-6956-1
USN-6957-1
USN-6979-1
USN-7019-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu