CVE-2024-35978: Bluetooth: Fix memory leak in hci_req_sync_complete()
Published May 20, 2024
·Updated
Bluetooth: Fix memory leak in hcireqsynccomplete()
Affected Software
20 affected componentsFixes available
Linux Linux kernel>=4.1<4.19.313
Linux Linux kernel>=4.20<5.4.275
Linux Linux kernel>=5.5<5.10.216
Linux Linux kernel>=5.11<5.15.156
Linux Linux kernel>=5.16<6.1.87
Linux Linux kernel>=6.2<6.6.28
Linux Linux kernel>=6.7<6.8.7
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
redhat/kernel<4.19.313
4.19.313
redhat/kernel<5.4.275
5.4.275
redhat/kernel<5.10.216
5.10.216
redhat/kernel<5.15.156
5.15.156
redhat/kernel<6.1.87
6.1.87
redhat/kernel<6.6.28
6.6.28
redhat/kernel<6.8.7
6.8.7
redhat/kernel<6.9
6.9
Microsoft cbl2 kernel 5.15.153.1-2
Microsoft azl3 kernel 6.6.35.1-5
Microsoft azl3 kernel 6.6.22.1-2
Microsoft cbl2 kernel 5.15.158.1-1
Remediation
Event History
May 20, 2024
CVE Published
via MITRE·09:42 AM
Data Sourced
via MITRE·09:42 AM
Description
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·04:19 PM
DescriptionSeverityAffected Software
May 24, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jul 11, 2024
Data Sourced
via Launchpad·07:49 PM
Description
Apr 27, 2025
Data Sourced
via Ubuntu·12:25 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35978?
CVE-2024-35978 is considered to have a moderate severity due to a memory leak in the Linux kernel Bluetooth subsystem.
2
How do I fix CVE-2024-35978?
To fix CVE-2024-35978, update your Linux kernel to one of the patched versions listed in the advisory.
3
What versions of the Linux kernel are affected by CVE-2024-35978?
CVE-2024-35978 affects multiple versions of the Linux kernel between 4.1 and 6.12.x inclusive.
4
What component is impacted by CVE-2024-35978?
CVE-2024-35978 impacts the Bluetooth component within the Linux kernel.
5
Can CVE-2024-35978 be exploited remotely?
While CVE-2024-35978 involves a memory leak, it does not inherently provide an exploit vector for remote attacks.