CVE-2024-56757
MEDIUMLinux Kernel < 6.12.8 - Denial of Service via Improper Bluetooth Interface Release
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow when usb disconnect MediaTek claim an special usb intr interface for ISO data transmission. The interface need to be released before unregistering hci device when usb disconnect. Removing BT usb dongle without properly releasing the interface may cause Kernel panic while unregister hci device.
References (2)
Core 2
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
11.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-404
Status
published
Products (8)
linux/Kernel
6.11.0 - 6.12.8linux
Linux/Linux
< 6.11
Linux/Linux
6.11
Linux/Linux
6.12.8 - 6.12.*
Linux/Linux
6.13
Linux/Linux
ceac1cb0259de682d78f5c784ef8e0b13022e9d9 - 489304e67087abddc2666c5af0159cb95afdcf59
Linux/Linux
ceac1cb0259de682d78f5c784ef8e0b13022e9d9 - cc569d791ab2a0de74f76e470515d25d24c9b84b
linux/linux_kernel
< 6.12.8
Published
Jan 06, 2025
Tracked Since
Feb 18, 2026