cbcvebase.
CVE-2024-26889
published 2024-04-17

CVE-2024-26889: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix possible buffer overflow struct hci_dev_info has a fixed size…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.1th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix possible buffer overflow struct hci_dev_info has a fixed size name[8] field so in the event that hdev->name is bigger than that strcpy would attempt to write past its size, so this fixes this problem by switching to use strscpy.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 194ab82c1ea187512ff2f822124bd05b63fc9f76 < 6d5a9d4a7bcbb7534ce45a18a52e7bd23e69d8ac6d5a9d4a7bcbb7534ce45a18a52e7bd23e69d8ac
linuxlinux>= 4.14.328 < 4.154.15
linuxlinux>= 4.19.297 < 4.19.3114.19.311
linuxlinux>= 5.10.199 < 5.10.2145.10.214
linuxlinux>= 5.15.137 < 5.15.1535.15.153
linuxlinux>= 5.4.259 < 5.4.2735.4.273
linuxlinux>= 6.1.60 < 6.26.2
linuxlinux>= 6.5.9 < 6.66.6
linuxlinux>= b48595f5b1c6e81e06e164e7d2b7a30b1776161e < 54a03e4ac1a41edf8a5087bd59f8241b0de96d3d54a03e4ac1a41edf8a5087bd59f8241b0de96d3d
linuxlinux>= bbec1724519ecd9c468d1186a8f30b7567175bfb < 2e845867b4e279eff0a19ade253390470e07e8a12e845867b4e279eff0a19ade253390470e07e8a1
linuxlinux>= dcda165706b9fbfd685898d46a6749d7d397e0c0 < a41c8efe659caed0e21422876bbb6b73c15b5244a41c8efe659caed0e21422876bbb6b73c15b5244
linuxlinux>= dcda165706b9fbfd685898d46a6749d7d397e0c0 < 8c28598a2c29201d2ba7fc37539a7d41c264fb108c28598a2c29201d2ba7fc37539a7d41c264fb10
linuxlinux>= dcda165706b9fbfd685898d46a6749d7d397e0c0 < 2edce8e9a99dd5e4404259d52e754fdc97fb42c22edce8e9a99dd5e4404259d52e754fdc97fb42c2
linuxlinux>= dcda165706b9fbfd685898d46a6749d7d397e0c0 < 81137162bfaa7278785b24c1fd2e9e74f082e8e481137162bfaa7278785b24c1fd2e9e74f082e8e4
linuxlinux>= ffb060b136dd75a033ced0fc0aed2882c02e8b56 < d47e6c1932cee02954ea588c9f09fd5ecefeadfcd47e6c1932cee02954ea588c9f09fd5ecefeadfc
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.