CVE-2024-35964: Bluetooth: ISO: Fix not validating setsockopt user input
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix not validating setsockopt user input
Check user input length before copying data.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix not validating setsockopt user input
The Linux kernel CVE team has assigned CVE-2024-35964 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024052021-CVE-2024-35964-25e2@gregkh/T
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35964?
CVE-2024-35964 is classified as a medium severity vulnerability due to improper user input validation.
How do I fix CVE-2024-35964?
To fix CVE-2024-35964, upgrade to the patched Linux kernel versions 5.10.223-1, 5.10.226-1, 6.1.119-1 or later.
What software is affected by CVE-2024-35964?
CVE-2024-35964 affects specific versions of the Linux kernel, including 5.10, 6.1, and 6.12.
What type of vulnerability is CVE-2024-35964?
CVE-2024-35964 is a validation vulnerability in the Bluetooth subsystem of the Linux kernel.
Can CVE-2024-35964 be exploited remotely?
Yes, CVE-2024-35964 has the potential to be exploited remotely due to its nature involving Bluetooth communication.