cbcvebase.
CVE-2024-35856
published 2024-05-17

CVE-2024-35856: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would free the skb on error so the caller don't have to free it again otherwise it would cause the double free of skb. Reported-by : Dan Carpenter

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.9-1 (forky)linux 6.8.9-1 (forky)
linuxlinux
linuxlinux>= 0b70151328781a89c89e4cf3fae21fc0e98d869e < 80dfef128cb9f1b1ef67c0fe8c8deb4ea7ad30c180dfef128cb9f1b1ef67c0fe8c8deb4ea7ad30c1
linuxlinux>= 0b70151328781a89c89e4cf3fae21fc0e98d869e < e20093c741d8da9f6390dd45d75b779861547035e20093c741d8da9f6390dd45d75b779861547035
linuxlinux>= 0b70151328781a89c89e4cf3fae21fc0e98d869e < 18bdb386a1a30e7a3d7732a98e45e69cf6b5710d18bdb386a1a30e7a3d7732a98e45e69cf6b5710d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.6 < 6.6.306.6.30
linuxlinux_kernel>= 6.7 < 6.8.96.8.9
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.