ZDI-CAN-24547: ZDI-24-1648: Linux Kernel Bluetooth HCI Request Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24547?
ZDI-CAN-24547 has a CVSS rating of 7.5, indicating a high severity level.
How do I fix ZDI-CAN-24547?
To fix ZDI-CAN-24547, apply the latest patches from your Linux distribution that address the Bluetooth HCI request race condition.
What systems are affected by ZDI-CAN-24547?
ZDI-CAN-24547 affects installations of the Linux Kernel that include the vulnerable Bluetooth HCI components.
Who can exploit the ZDI-CAN-24547 vulnerability?
Local attackers with the ability to execute high-privileged code are capable of exploiting the ZDI-CAN-24547 vulnerability.
What type of attack does ZDI-CAN-24547 enable?
ZDI-CAN-24547 enables local privilege escalation, allowing attackers to gain elevated permissions on the system.