cbcvebase.
CVE-2024-35967
published 2024-05-20

CVE-2024-35967: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix not validating setsockopt user input syzbot reported…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix not validating setsockopt user input syzbot reported sco_sock_setsockopt() is copying data without checking user input length. BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in sco_sock_setsockopt+0xc0b/0xf90 net/bluetooth/sco.c:893 Read of size 4 at addr ffff88805f7b15a3 by task syz-executor.5/12578

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= b96e9c671b05f95126753a22145d4509d45ca197 < b0e30c37695b614bee69187f86eaf250e36606ceb0e30c37695b614bee69187f86eaf250e36606ce
linuxlinux>= b96e9c671b05f95126753a22145d4509d45ca197 < 2c2dc87cdebef3fe3b9d7a711a984c70e376e32e2c2dc87cdebef3fe3b9d7a711a984c70e376e32e
linuxlinux>= b96e9c671b05f95126753a22145d4509d45ca197 < 7bc65d23ba20dcd7ecc094a12c181e594e5eb3157bc65d23ba20dcd7ecc094a12c181e594e5eb315
linuxlinux>= b96e9c671b05f95126753a22145d4509d45ca197 < 72473db90900da970a16ee50ad23c2c38d107d8c72473db90900da970a16ee50ad23c2c38d107d8c
linuxlinux>= b96e9c671b05f95126753a22145d4509d45ca197 < 419a0ffca7010216f0fc265b08558d7394fa0ba7419a0ffca7010216f0fc265b08558d7394fa0ba7
linuxlinux>= b96e9c671b05f95126753a22145d4509d45ca197 < 51eda36d33e43201e7a4fd35232e069b2c850b0151eda36d33e43201e7a4fd35232e069b2c850b01
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-204.2245.4.0-204.224
linuxlinux_kernel>= 0 < 5.15.0-130.1405.15.0-130.140
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 3.8 < 5.10.2165.10.216
linuxlinux_kernel>= 5.11 < 5.15.1785.15.178
linuxlinux_kernel>= 5.16 < 6.1.876.1.87
linuxlinux_kernel>= 6.2 < 6.6.286.6.28
linuxlinux_kernel>= 6.7 < 6.8.76.8.7

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.