cbcvebase.
CVE-2024-27416
published 2024-05-17

CVE-2024-27416: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.35%
28.0th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 1769ac55dbf3114d5bf79f11bd5dca80ee263f9c < 79820a7e1e057120c49be07cbe10643d0706b25979820a7e1e057120c49be07cbe10643d0706b259
linuxlinux>= 1ef071526848cc3109ade63268854cd7c20ece0c < c3df637266df29edee85e94cab5fd7041e5753bac3df637266df29edee85e94cab5fd7041e5753ba
linuxlinux>= 25e5d2883002e235f3378b8592aad14aeeef898c < 30a5e812f78e3d1cced90e1ed750bf027599205f30a5e812f78e3d1cced90e1ed750bf027599205f
linuxlinux>= 4.14.328 < 4.154.15
linuxlinux>= 4.19.297 < 4.19.3094.19.309
linuxlinux>= 40a33a129d99639921ce00d274cca44ba282f1ac < df193568d61234c81de7ed4d540c01975de60277df193568d61234c81de7ed4d540c01975de60277
linuxlinux>= 5.10.199 < 5.10.2125.10.212
linuxlinux>= 5.15.137 < 5.15.1515.15.151
linuxlinux>= 5.4.259 < 5.4.2715.4.271
linuxlinux>= 6.1.60 < 6.1.816.1.81
linuxlinux>= 6.5.9 < 6.66.6
linuxlinux>= c7f59461f5a78994613afc112cdd73688aef9076 < fba268ac36ab19f9763ff90d276cde0ce6cd5f31fba268ac36ab19f9763ff90d276cde0ce6cd5f31
linuxlinux>= c7f59461f5a78994613afc112cdd73688aef9076 < 8e2758cc25891d2b76717aaf89b40ed215de188c8e2758cc25891d2b76717aaf89b40ed215de188c
linuxlinux>= c7f59461f5a78994613afc112cdd73688aef9076 < 7e74aa53a68bf60f6019bd5d9a9a1406ec4d48657e74aa53a68bf60f6019bd5d9a9a1406ec4d4865
linuxlinux>= ccb8618c972f941ebc6b2b9db491025b3369efcb < afec8f772296dd8e5a2a6f83bbf99db1b9ca877fafec8f772296dd8e5a2a6f83bbf99db1b9ca877f
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.