cbcvebase.
CVE-2024-35966
published 2024-05-20

CVE-2024-35966: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix not validating setsockopt user input syzbot reported…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix not validating setsockopt user input syzbot reported rfcomm_sock_setsockopt_old() is copying data without checking user input length. BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in rfcomm_sock_setsockopt_old net/bluetooth/rfcomm/sock.c:632 [inline] BUG: KASAN: slab-out-of-bounds in rfcomm_sock_setsockopt+0x893/0xa70 net/bluetooth/rfcomm/sock.c:673 Read of size 4 at addr ffff8880209a8bc3 by task syz-executor632/5064

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= bb23c0ab824653be4aa7dfca15b07b3059717004 < d072ea24748189cd8f4a9c3f585ca9af073a0838d072ea24748189cd8f4a9c3f585ca9af073a0838
linuxlinux>= bb23c0ab824653be4aa7dfca15b07b3059717004 < 00767fbd67af70d7a550caa5b12d9515fa978bab00767fbd67af70d7a550caa5b12d9515fa978bab
linuxlinux>= bb23c0ab824653be4aa7dfca15b07b3059717004 < eea40d33bf936a5c7fb03c190e61e0cfee00e872eea40d33bf936a5c7fb03c190e61e0cfee00e872
linuxlinux>= bb23c0ab824653be4aa7dfca15b07b3059717004 < 4ea65e2095e9bd151d0469328dd7fc2858feb5464ea65e2095e9bd151d0469328dd7fc2858feb546
linuxlinux>= bb23c0ab824653be4aa7dfca15b07b3059717004 < c3f787a3eafe519c93df9abbb0ca5145861c8d0fc3f787a3eafe519c93df9abbb0ca5145861c8d0f
linuxlinux>= bb23c0ab824653be4aa7dfca15b07b3059717004 < a97de7bff13b1cc825c1b1344eaed8d6c2d3e695a97de7bff13b1cc825c1b1344eaed8d6c2d3e695
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-204.2245.4.0-204.224
linuxlinux_kernel>= 0 < 5.15.0-130.1405.15.0-130.140
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 2.6.30 < 5.10.2345.10.234
linuxlinux_kernel>= 5.11 < 5.15.1785.15.178
linuxlinux_kernel>= 5.16 < 6.1.1076.1.107
linuxlinux_kernel>= 6.2 < 6.6.476.6.47
linuxlinux_kernel>= 6.7 < 6.8.76.8.7

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.