PT-2024-4113 · Linux+7 · Linux Kernel+7

Luiz Augusto Von Dentz

+1

·

Published

2024-05-14

·

Updated

2026-03-14

·

CVE-2024-36968

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue is related to a div-by-zero and integer overflow vulnerability in the l2cap le flowctl init() function. This vulnerability can be caused by an invalid hdev->le mtu value. To fix this, the MTU is moved from hci dev to hci conn to validate it and stop the connection process earlier if it is invalid. Additionally, a missing validation in read buffer size() is added to return an error value if the validation fails. The hci conn add() function now returns ERR PTR() as it can fail due to a kzalloc failure or an invalid MTU value.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.37 or later. As a temporary workaround, consider disabling the l2cap le flowctl init() function until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the hdev->le mtu parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

RCE

Integer Overflow

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-10855
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-43354
BDU:2024-04565
CVE-2024-36968
ECHO-B457-3FC7-E707
INFSA-2025_6966
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1737
OESA-2024-1738
OESA-2024-1766
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:1293-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
SUSE-SU-2025_1293-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1
USN-7159-1
USN-7159-2
USN-7159-3
USN-7159-4
USN-7159-5
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7183-1
USN-7184-1
USN-7185-1
USN-7185-2
USN-7186-1
USN-7186-2
USN-7194-1
USN-7195-1
USN-7195-2

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu