bugzilla.openanolis.cn
https://bugzilla.openanolis.cn/show_bug.cgi?id=7956 CVE-2024-22099
MEDIUM
NULL pointer deference in rfcomm_check_security in Linux kernel
Record summary
CVE-2024-22099 has a selected CVSS score of 6.3 (medium).
Description
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12-rc2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | v2.6.12-rc2 to < v6.8-rc1 | affected |
SIMATIC S7-1500 TM MFP - GNU/Linux subsystemBrowse Siemens / SIMATIC S7-1500 TM MFP - GNU/Linux subsystemDefault status: unknown | CVE List | Before * | affected |
References
7cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-265688.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IVVYSTEVMPYGF6GDSOD44MUXZXAZHOHB lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSXNF4RLEFLH35BFUQGYXRRVHHUIVBAE nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-22099