CVE-2024-35965: Bluetooth: L2CAP: Fix not validating setsockopt user input
Published May 20, 2024
·Updated
Bluetooth: L2CAP: Fix not validating setsockopt user input
Affected Software
11 affected componentsFixes available
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
redhat/kernel<6.1.87
6.1.87
redhat/kernel<6.8.7
6.8.7
redhat/kernel<6.9
6.9
Linux Linux kernel>=2.6.39<5.10.227
Linux Linux kernel>=5.11<6.1.87
Linux Linux kernel>=6.2<6.6.55
Linux Linux kernel>=6.7<6.8.7
Linux Linux kernel=6.9-rc1
Linux Linux kernel=6.9-rc2
Linux Linux kernel=6.9-rc3
Remediation
Event History
May 20, 2024
CVE Published
via MITRE·09:41 AM
Data Sourced
via MITRE·09:41 AM
Description
Data Sourced
via NVD·10:15 AM
Description
Data Sourced
via NVD·10:15 AM
RemedySeverityWeaknessAffected Software
Data Sourced
via Red Hat·04:48 PM
DescriptionSeverityAffected Software
Jul 15, 2024
Data Sourced
via Launchpad·07:48 PM
Description
May 1, 2025
Data Sourced
via Ubuntu·12:24 AM
RemedyDescriptionSeverityAffected Software
Sep 27, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35965?
CVE-2024-35965 is categorized with a medium severity due to the potential for user input validation issues in the Linux kernel's Bluetooth functionality.
2
How do I fix CVE-2024-35965?
To fix CVE-2024-35965, update the Linux kernel to versions 6.1.123-1, 6.1.128-1, or 6.12.12-1 depending on your distribution.
3
What systems are affected by CVE-2024-35965?
CVE-2024-35965 affects Linux kernel versions up to 5.10.226-1, particularly those using Bluetooth L2CAP.
4
What is the nature of the vulnerability in CVE-2024-35965?
CVE-2024-35965 is due to the lack of validation of user input length in the Bluetooth L2CAP implementation.
5
Are there any workarounds for CVE-2024-35965?
No specific workarounds are recommended for CVE-2024-35965; upgrading the kernel is the advised course of action.