CVE-2024-38620: Bluetooth: HCI: Remove HCI_AMP support
Bluetooth: HCI: Remove HCIAMP support
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.22-1Fixed in 6.12.25-1 - Remove
Remove
Linux kernel Bluetooth HCI: HCI_AMP supportfrom your environment.Remove HCI_AMP support in the Linux kernel Bluetooth HCI layer, including removing the capability of creating AMP controllers.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38620?
CVE-2024-38620 has not been assigned a severity level yet, but it addresses a removal of unsupported features in the Linux kernel.
How do I fix CVE-2024-38620?
To fix CVE-2024-38620, update your Linux kernel to version 6.12.10-1 or 6.12.11-1 if you are using Debian.
Which software versions are affected by CVE-2024-38620?
CVE-2024-38620 affects the Linux kernel versions 5.10.223-1, 5.10.226-1, 6.1.119-1, and 6.1.123-1.
Does CVE-2024-38620 have any known exploit methods?
Currently, there are no known exploits for CVE-2024-38620 as it pertains to the removal of obsolete Bluetooth support.
Is CVE-2024-38620 a critical vulnerability?
CVE-2024-38620 is not considered critical as it involves the removal of unused HCI_AMP features, not an active attack vector.