CVE-2024-36033

HIGH

Linux Kernel 6.7-6.8.9 - Information Disclosure via Bluetooth QCA Board ID Fetch

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching board id Add the missing sanity check when fetching the board id to avoid leaking slab data when later requesting the firmware.

Scores

CVSS v3 7.1
EPSS 0.0025
EPSS Percentile 15.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (12)
linux/Kernel 6.7.0 - 6.8.10linux
Linux/Linux < 6.7
Linux/Linux 6.7
Linux/Linux 6.8.10 - 6.8.*
Linux/Linux 6.9
Linux/Linux a381ee26d7c70dbc048cd17c4e0f40619118ff1f - ba307abed5e09759845c735ba036f8c12f55b209
Linux/Linux a7f8dedb4be2cc930a29af24427b885405ecd15d - 0adcf6be1445ed50bfd4a451a7a782568f270197
Linux/Linux a7f8dedb4be2cc930a29af24427b885405ecd15d - f30c37cb4549baf8377434892d520fe7769bdba7
Linux/Linux ad643241d455fdd2516d46cfa54bd0c5e504fc86 - bcccdc947d2ca5972b1e92d0dea10803ddc08ceb
Linux/Linux c3c1bd421db6187ee455995bfbf1ba16d98f5e6b - a3dff121a7f5104c4c2d47edaa2351837ef645dd
... and 2 more
Published May 30, 2024
Tracked Since Feb 18, 2026