PT-2024-36898 · Linux+4 · Linux Kernel+4

Published

2024-11-14

·

Updated

2026-05-26

·

CVE-2024-56591

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved. The issue is related to the Bluetooth component, specifically in the hci conn module. The fix involves using disable delayed work sync instead of cancel delayed work sync to not only cancel ongoing work but also disable new submissions. This change is necessary because the object holding the work is about to be freed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
AZL-62630
AZL-68276
BDU:2026-01423
CVE-2024-56591
ECHO-34A5-23C6-0840
INFSA-2025_6966
OESA-2025-2465
OESA-2025-2466
OESA-2025-2467
RHSA-2025:6966
RHSA-2025_6966
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Hat
Ubuntu