CVE-2024-36032: Bluetooth: qca: fix info leak when fetching fw build id
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: qca: fix info leak when fetching fw build id
Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case the build-info reply is malformed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36032?
CVE-2024-36032 has a medium severity rating due to the potential for an information leak affecting confidentiality.
How do I fix CVE-2024-36032?
To address CVE-2024-36032, update the Linux kernel to versions 5.10.223-1, 5.10.234-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.17-1.
What systems are affected by CVE-2024-36032?
CVE-2024-36032 affects Debian Linux systems running specific older versions of the Linux kernel.
What is the nature of the vulnerability in CVE-2024-36032?
CVE-2024-36032 involves an information leak due to missing sanity checks in the Bluetooth subsystem of the Linux kernel.
Is there a public patch available for CVE-2024-36032?
Yes, a patch for CVE-2024-36032 has been released and can be applied by updating to the specified kernel versions.