CVE-2024-26888: Bluetooth: msft: Fix memory leak
Published Apr 17, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: msft: Fix memory leak
Fix leaking buffer allocated to send MSFTOPLEMONITORADVERTISEMENT.
Affected Software
5 affected componentsFixes available
Linux Linux kernel>=6.4.16<6.5
Linux Linux kernel>=6.5.3<6.6.23
Linux Linux kernel>=6.7<6.7.11
Linux Linux kernel>=6.8<6.8.2
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Remediation
Event History
Apr 17, 2024
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
Description
Jun 8, 2024
Data Sourced
via Launchpad·01:10 AM
Description
Jan 14, 2025
Data Sourced
via Ubuntu·05:53 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·02:14 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-26888?
The severity of CVE-2024-26888 is classified as medium due to the potential for a memory leak.
2
What are the affected versions for CVE-2024-26888?
CVE-2024-26888 affects Linux Kernel versions between 6.4.16 and 6.5, 6.5.3 and 6.6.23, 6.7 and 6.7.11, as well as 6.8 and 6.8.2.
3
How do I fix CVE-2024-26888?
To fix CVE-2024-26888, you should update the Linux Kernel to one of the patched versions such as 5.10.223-1 or 6.12.11-1.
4
Is there a workaround for CVE-2024-26888?
Currently, there is no known workaround for CVE-2024-26888, and updating the kernel is the recommended action.
5
What type of vulnerability is CVE-2024-26888?
CVE-2024-26888 is a memory leak vulnerability in the Bluetooth module of the Linux kernel.