CVE-2024-24859: Race condition vulnerability in Linux kernel bluetooth sniff_{min,max}_interval_set()
A race condition was found in the Linux kernel's net/bluetooth in sniff{min,max}intervalset() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service.
Other sources
A race condition was found in the Linux kernel's net/bluetooth in sniff{min,max}intervalset() function. This can result in a bluetooth sniffing exception issue, possibly leading to denial of service.
Reference: https://bugzilla.openanolis.cn/showbug.cgi?id=8153
Upstream patch: https://lore.kernel.org/lkml/20231222162931.6553-1-2045gemini@gmail.com/
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24859?
CVE-2024-24859 has been classified as a denial of service vulnerability in the Linux kernel's Bluetooth module.
How do I fix CVE-2024-24859?
To mitigate CVE-2024-24859, update the kernel to versions 6.8, 6.12.10-1, 6.12.11-1 or to the patched versions available in your distribution's repositories.
Which systems are affected by CVE-2024-24859?
CVE-2024-24859 affects various Linux kernel versions, specifically those under 6.8 and including certain Debian and Red Hat kernel versions.
What specific function in the Linux kernel is related to CVE-2024-24859?
CVE-2024-24859 is related to the sniff_{min,max}_interval_set() function in the Linux kernel's Bluetooth module.
Can CVE-2024-24859 lead to exploitation in practical scenarios?
Yes, CVE-2024-24859 could lead to denial of service conditions if exploited, affecting the stability of Bluetooth operations.