CVE-2024-56757

MEDIUM

Linux Kernel < 6.12.8 - Denial of Service via Improper Bluetooth Interface Release

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow when usb disconnect MediaTek claim an special usb intr interface for ISO data transmission. The interface need to be released before unregistering hci device when usb disconnect. Removing BT usb dongle without properly releasing the interface may cause Kernel panic while unregister hci device.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (8)
linux/Kernel 6.11.0 - 6.12.8linux
Linux/Linux < 6.11
Linux/Linux 6.11
Linux/Linux 6.12.8 - 6.12.*
Linux/Linux 6.13
Linux/Linux ceac1cb0259de682d78f5c784ef8e0b13022e9d9 - 489304e67087abddc2666c5af0159cb95afdcf59
Linux/Linux ceac1cb0259de682d78f5c784ef8e0b13022e9d9 - cc569d791ab2a0de74f76e470515d25d24c9b84b
linux/linux_kernel < 6.12.8
Published Jan 06, 2025
Tracked Since Feb 18, 2026