PT-2024-4090 · Linux+6 · Linux Kernel+6
Sungwoo Kim
·
Published
2024-05-03
·
Updated
2026-05-26
·
CVE-2024-36012
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a slab-use-after-free vulnerability in the
msft do close() function. This vulnerability is caused by a race condition where the msft->data is freed in hci release dev() but still used in msft do close(). The vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. Technical details about exploitation include the use of the mutex lock() function on a freed msft->filter lock and the kfree() function to free the msft data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu