CVE-2024-43884: Bluetooth: MGMT: Add error handling to pair_device()
Bluetooth: MGMT: Add error handling to pairdevice()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43884?
CVE-2024-43884 has been classified as having a moderate severity due to the potential for a NULL pointer dereference causing a crash.
How do I fix CVE-2024-43884?
To fix CVE-2024-43884, update to the recommended versions of the Linux kernel as specified in the vulnerability report.
What causes the vulnerability CVE-2024-43884?
CVE-2024-43884 is caused by the hci_conn_params_add() function not checking for a NULL value, leading to potential NULL pointer dereferences.
Which versions of the Linux kernel are affected by CVE-2024-43884?
CVE-2024-43884 affects several versions including prior to 5.10.226-1, 6.1.123-1, and specific release candidates of 6.11.
Is there a workaround for CVE-2024-43884?
There is no official workaround for CVE-2024-43884; upgrading to a patched version of the kernel is necessary.