First published: Tue Dec 17 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always request user confirmation with confirm_hint set since the likes of bluetoothd have dedicated policy around JUST_WORKS method (e.g. main.conf:JustWorksRepairing). CVE: CVE-2024-8805
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=92516cd97fd4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53144 has been rated as medium severity due to its potential impact on Bluetooth communication in the Linux kernel.
To fix CVE-2024-53144, update your Linux kernel to the latest version that resolves this vulnerability.
CVE-2024-53144 affects versions of the Linux kernel from 92516cd97fd4 upwards.
CVE-2024-53144 pertains to a vulnerability in the Bluetooth subsystem of the Linux kernel related to Just Works pairing.
There are no known workarounds for CVE-2024-53144; the recommended action is to apply the kernel update.