bugzilla.openanolis.cn
https://bugzilla.openanolis.cn/show_bug.cgi?id=8151 CVE-2024-24860
MEDIUM
Race condition vulnerability in Linux kernel bluetooth driver in {min,max}_key_size_set()
Record summary
CVE-2024-24860 has a selected CVSS score of 4.6 (medium).
Description
A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | v5.6-rc1 to < v6.8-rc1 | affected |
References
3lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-24860