PT-2024-9012 · Linux+7 · Linux Kernel+7

Johan Hovold

·

Published

2024-05-30

·

Updated

2026-03-14

·

CVE-2024-36880

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the qca component of the Linux kernel's Bluetooth functionality, where missing firmware sanity checks can lead to memory corruption beyond the vmalloced buffer when parsing firmware files. This can result in a denial of service. The vulnerability is caused by improper input validation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-10694
CVE-2024-36880
INFSA-2025_6966
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-2029
OESA-2024-2031
OESA-2024-2258
OESA-2024-2296
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20249-1
USN-6949-1
USN-6949-2
USN-6950-1
USN-6950-2
USN-6950-3
USN-6950-4
USN-6952-1
USN-6952-2
USN-6955-1
USN-6956-1
USN-6957-1
USN-7019-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu