CVE-2024-26903NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
OSV7.0OSV6.5
EPSS
0.0%
top 98.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateAug 28

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security During our fuzz testing of the connection and disconnection process at the RFCOMM layer, we discovered this bug. By comparing the packets from a normal connection and disconnection process with the testcase that triggered a KASAN report. We analyzed the cause of this bug as follows: 1. In the packets captured during a normal connection, the host sends a `Read Encr

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

Patches

🔴Vulnerability Details

22
OSV
linux-oracle vulnerabilities2024-08-28
OSV
linux-azure, linux-azure-4.15 vulnerabilities2024-08-23
OSV
linux-aws, linux-aws-hwe vulnerabilities2024-08-22
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2024-08-21
OSV
linux, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm vulnerabilities2024-08-21

📋Vendor Advisories

22
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-08-28
Ubuntu
Linux kernel (Azure) vulnerabilities2024-08-23
Ubuntu
Linux kernel (AWS) vulnerabilities2024-08-22
Ubuntu
Linux kernel vulnerabilities2024-08-21
Ubuntu
Linux kernel vulnerabilities2024-07-26

💬Community

1
Bugzilla
CVE-2024-26903 kernel: Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security2024-04-17