CVE-2024-36033: Bluetooth: qca: fix info leak when fetching board id
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: qca: fix info leak when fetching board id
Add the missing sanity check when fetching the board id to avoid leaking slab data when later requesting the firmware.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36033?
CVE-2024-36033 has been rated as having a high severity due to its potential for information leakage.
How do I fix CVE-2024-36033?
To remediate CVE-2024-36033, update your Linux kernel to one of the patched versions, such as 5.10.234-1 or later.
What software versions are affected by CVE-2024-36033?
CVE-2024-36033 affects several Linux kernel versions including 5.10.223-1, 5.10.234-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, and 6.12.16-1.
What type of vulnerability is CVE-2024-36033?
CVE-2024-36033 is an information disclosure vulnerability related to the Bluetooth subsystem in the Linux kernel.
Is CVE-2024-36033 actively exploited in the wild?
As of now, there are no reports indicating that CVE-2024-36033 is actively exploited in the wild.