CVE-2024-42133: Bluetooth: Ignore too large handle values in BIG
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Ignore too large handle values in BIG
hcilebigsyncestablishedevt is necessary to filter out cases where the handle value is belonging to ida id range, otherwise ida will be erroneously released in hciconncleanup.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.39 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9.9 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.10
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42133?
CVE-2024-42133 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-42133?
To fix CVE-2024-42133, you should update your Linux kernel to a patched version as specified in the latest security advisories.
What affected versions are vulnerable to CVE-2024-42133?
CVE-2024-42133 affects Linux kernel versions from 6.5.12 up to 6.10-rc6.
Is CVE-2024-42133 a local or remote exploit?
CVE-2024-42133 can potentially be exploited remotely through Bluetooth features.
What kind of impact does CVE-2024-42133 have on the system?
The impact of CVE-2024-42133 could lead to unintended system behavior and resource mismanagement.