CVE-2024-35963: Bluetooth: hci_sock: Fix not validating setsockopt user input
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcisock: Fix not validating setsockopt user input
Check user input length before copying data.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcisock: Fix not validating setsockopt user input
The Linux kernel CVE team has assigned CVE-2024-35963 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024052021-CVE-2024-35963-7934@gregkh/T
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8.7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35963?
CVE-2024-35963 is categorized as a medium severity vulnerability due to improper input validation in the Bluetooth subsystem of the Linux kernel.
How do I fix CVE-2024-35963?
To remediate CVE-2024-35963, update to the fixed versions of the Linux kernel including 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
What systems are affected by CVE-2024-35963?
CVE-2024-35963 affects Linux kernel versions prior to the fixed releases listed in the vulnerability details.
What does CVE-2024-35963 affect in the Linux kernel?
CVE-2024-35963 specifically affects the Bluetooth hci_sock feature by not properly validating user input in the setsockopt function.
Who is responsible for addressing CVE-2024-35963?
It is the responsibility of system administrators and users to apply the necessary kernel updates to mitigate CVE-2024-35963.