CVE-2024-27416: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcievent: Fix handling of HCIEVIOCAPAREQUEST
If we received HCIEVIOCAPAREQUEST while HCIOPREADREMOTEEXTFEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27416?
CVE-2024-27416 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-27416?
To fix CVE-2024-27416, upgrade to the patched versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
What effect does CVE-2024-27416 have on Bluetooth functionality?
CVE-2024-27416 affects the handling of HCI_EV_IO_CAPA_REQUEST, which may lead to incorrect assumptions about remote device capabilities.
Is CVE-2024-27416 a remote or local vulnerability?
CVE-2024-27416 is considered a local vulnerability, as it requires access to the Bluetooth functionality of the system.
Which versions of the Linux kernel are vulnerable to CVE-2024-27416?
Versions of the Linux kernel prior to the patched versions listed are vulnerable to CVE-2024-27416.