CVE-2024-35963Improper Validation of Specified Quantity in Input in Linux

Severity
7.1HIGHNVD
OSV8.8OSV6.8OSV5.5OSV4.7
EPSS
0.0%
top 99.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateApr 3

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sock: Fix not validating setsockopt user input Check user input length before copying data.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages6 packages

NVDlinux/linux_kernel5.166.1.113+3
Debianlinux/linux_kernel< 6.1.115-1+2
Ubuntulinux/linux_kernel< 5.4.0-204.224+2
CVEListV5linux/linux09572fca7223bcf32c9f0d5e100d8381a81d55f4781f3a97a38a338bc893b6db7f9f9670bf1a9e37+4
debiandebian/linux< linux 6.1.115-1 (bookworm)

Patches

🔴Vulnerability Details

19
OSV
linux-iot vulnerabilities2025-04-03
OSV
linux-xilinx-zynqmp vulnerabilities2025-01-27
OSV
linux-raspi-5.4 vulnerabilities2025-01-15
OSV
linux-azure-5.4 vulnerabilities2025-01-14
OSV
linux-azure, linux-intel-iotg-5.15 vulnerabilities2025-01-09

📋Vendor Advisories

18
Ubuntu
Linux kernel (IoT) vulnerabilities2025-04-03
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2025-01-27
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-01-15
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-14
Ubuntu
Linux kernel vulnerabilities2025-01-09

💬Community

1
Bugzilla
CVE-2024-35963 kernel: Bluetooth: hci_sock: Fix not validating setsockopt user input2024-05-20