PT-2024-6561 · Bluez+7 · Bluez+7

Michael Randrianantenaina

·

Published

2024-09-17

·

Updated

2026-03-14

·

CVE-2024-8805

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BlueZ versions prior to a currently unspecified fix Linux kernel versions 6.1 through 6.1.119-1~deb11u1 Linux kernel (Azure) (affected versions not specified) Linux kernel (AWS) (affected versions not specified) Linux kernel (OEM) (affected versions not specified) Linux kernel (HWE) (affected versions not specified)
Description Multiple vulnerabilities exist within BlueZ and the Linux kernel. A critical vulnerability in BlueZ allows for remote code execution due to improper access control within the HID over GATT Profile. Authentication is not required for exploitation. Additionally, vulnerabilities have been discovered in the Linux kernel that could lead to privilege escalation, denial of service, or information leaks. Specifically, Debian 11 bullseye has received updates to address these kernel vulnerabilities, with fixes included in version 6.1.119-1~deb11u1. These vulnerabilities impact various Linux kernel configurations including Azure, AWS, OEM, and HWE.
Recommendations Upgrade BlueZ to the latest available version. Upgrade the Linux kernel to version 6.1.119-1~deb11u1 on Debian 11 bullseye systems. Apply available security updates for Linux kernel (Azure), Linux kernel (AWS), Linux kernel (OEM), and Linux kernel (HWE) configurations.

Fix

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12793
ALT-PU-2025-1398
BDU:2024-07705
CVE-2024-8805
DLA-4008-1
OPENSUSE-SU-2025_0117-1
OPENSUSE-SU-2025_0153-1
OPENSUSE-SU-2025_0154-1
OPENSUSE-SU-2025_0201-1
OPENSUSE-SU-2025_0202-1
OPENSUSE-SU-2025_0203-1
OPENSUSE-SU-2025_0229-1
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0576-1
OPENSUSE-SU-2025_0577-1
OPENSUSE-SU-2025_1422-1
OPENSUSE-SU-2025_1425-1
OPENSUSE-SU-2025_1445-1
OPENSUSE-SU-2025_1448-1
OPENSUSE-SU-2025_1449-1
OPENSUSE-SU-2025_1454-1
OPENSUSE-SU-2025_1468-1
SUSE-SU-2025:0117-1
SUSE-SU-2025:0153-1
SUSE-SU-2025:0154-1
SUSE-SU-2025:0201-1
SUSE-SU-2025:0201-2
SUSE-SU-2025:0202-1
SUSE-SU-2025:0203-1
SUSE-SU-2025:0229-1
SUSE-SU-2025:0230-1
SUSE-SU-2025:0231-1
SUSE-SU-2025:0236-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0555-1
SUSE-SU-2025:0556-1
SUSE-SU-2025:0576-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:1385-1
SUSE-SU-2025:1402-1
SUSE-SU-2025:1403-1
SUSE-SU-2025:1422-1
SUSE-SU-2025:1425-1
SUSE-SU-2025:1445-1
SUSE-SU-2025:1448-1
SUSE-SU-2025:1449-1
SUSE-SU-2025:1454-1
SUSE-SU-2025:1468-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20211-1
SUSE-SU-2025:20212-1
SUSE-SU-2025:20213-1
SUSE-SU-2025:20214-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025:20314-1
SUSE-SU-2025:4123-1
SUSE-SU-2025_0201-1
SUSE-SU-2025_0201-2
SUSE-SU-2025_0202-1
SUSE-SU-2025_0203-1
SUSE-SU-2025_0236-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7403-1
USN-7468-1
USN-7591-1
USN-7591-2
USN-7591-3
USN-7591-4
USN-7591-5
USN-7591-6
USN-7592-1
USN-7593-1
USN-7597-1
USN-7597-2
USN-7598-1
USN-7602-1
USN-7655-1
ZDI-24-1229
ZDI-24-1647

Affected Products

Alt Linux
Astra Linux
Bluez
Debian
Linuxmint
Red Os
Suse
Ubuntu