cbcvebase.
CVE-2024-26887
published 2024-04-17

CVE-2024-26887: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix memory leak This checks if CONFIG_DEV_COREDUMP is enabled before…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: Fix memory leak This checks if CONFIG_DEV_COREDUMP is enabled before attempting to clone the skb and also make sure btmtk_process_coredump frees the skb passed following the same logic.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.12-1 (forky)linux 6.7.12-1 (forky)
linuxlinux
linuxlinux>= 0b70151328781a89c89e4cf3fae21fc0e98d869e < 620b9e60e4b55fa55540ce852a0f3c9e6091dbbc620b9e60e4b55fa55540ce852a0f3c9e6091dbbc
linuxlinux>= 0b70151328781a89c89e4cf3fae21fc0e98d869e < b10e6f6b160a60b98fb7476028f5a95405bbd725b10e6f6b160a60b98fb7476028f5a95405bbd725
linuxlinux>= 0b70151328781a89c89e4cf3fae21fc0e98d869e < b08bd8f02a24e2b82fece5ac51dc1c3d9aa6c404b08bd8f02a24e2b82fece5ac51dc1c3d9aa6c404
linuxlinux>= 0b70151328781a89c89e4cf3fae21fc0e98d869e < 79f4127a502c5905f04da1f20a7bbe07103fb77c79f4127a502c5905f04da1f20a7bbe07103fb77c
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.6 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.