First published: Mon Feb 05 2024(Updated: )
A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Credit: security@openanolis.org security@openanolis.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.10-1 | |
Linux Kernel | <=5.5.19 | |
Linux Kernel | >=6.0<=6.7.2 |
https://github.com/torvalds/linux/commit/da9065caa594d https://github.com/torvalds/linux/commit/da9065caa594d
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24860 is considered a high severity vulnerability due to its potential to cause kernel panic and denial of service.
To fix CVE-2024-24860, update the Linux kernel to one of the patched versions listed in the vulnerability details.
CVE-2024-24860 affects various versions of the Linux kernel, particularly those prior to version 5.10.223-1 and those in specific version ranges.
CVE-2024-24860 can lead to a null pointer dereference, resulting in system instability and potential service interruptions.
As of now, there is no public indication that CVE-2024-24860 is being actively exploited in the wild, but it poses a significant risk.