First published: Mon Feb 05 2024(Updated: )
A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.
Credit: security@openanolis.org security@openanolis.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.10-1 6.12.11-1 | |
Linux Kernel | <=3.19.8 | |
Linux Kernel | >=6.0<=6.7.2 | |
Linux Kernel | =6.8-rc1 |
https://lore.kernel.org/lkml/20231222162310.6461-1-2045gemini@gmail.com/T/ https://lore.kernel.org/lkml/20231222162310.6461-1-2045gemini@gmail.com/T/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24857 has been classified with a medium severity due to the potential for integrity overflow issues.
To mitigate CVE-2024-24857, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
Linux kernel versions from 3.19.8 up to 6.8-rc1 are affected by CVE-2024-24857.
CVE-2024-24857 may lead to Bluetooth connection abnormalities or denial of service issues.
Yes, CVE-2024-24857 is a race condition vulnerability that affects the Bluetooth device driver in the Linux kernel.