CVE-2024-41062: bluetooth/l2cap: sync sock recv cb and release
bluetooth/l2cap: sync sock recv cb and release
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.101 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.42 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9.11 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.10
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41062?
CVE-2024-41062 is considered a high severity vulnerability due to potential unauthorized access and data corruption issues.
How do I fix CVE-2024-41062?
To fix CVE-2024-41062, you should update the Linux kernel to a patched version, specifically one of the recommended versions such as 6.1.123-1 or later.
Which systems are affected by CVE-2024-41062?
CVE-2024-41062 affects Debian systems running specific versions of the Linux kernel below 5.10.223-1 and 5.10.226-1.
What components are involved in CVE-2024-41062?
CVE-2024-41062 involves the Bluetooth L2CAP implementation within the Linux kernel, particularly regarding socket handling.
Can CVE-2024-41062 be exploited remotely?
Yes, CVE-2024-41062 can potentially be exploited remotely if proper security measures are not implemented.