cbcvebase.
CVE-2024-36012
published 2024-05-23

CVE-2024-36012: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do_close() Tying the msft->data lifetime…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do_close() Tying the msft->data lifetime to hdev by freeing it in hci_release_dev() to fix the following case: [use] msft_do_close() msft = hdev->msft_data; if (!msft) ...(1) filter_lock); ...(4) msft_data; hdev->msft_data = NULL; ...(2) kfree(msft); ...(3) <- msft is freed. BUG: KASAN: slab-use-after-free in __mutex_lock_common kernel/locking/mutex.c:587 [inline] BUG: KASAN: slab-use-after-free in __mutex_lock+0x8f/0xc30 kernel/locking/mutex.c:752 Read of size 8 at addr ffff888106cbbca8 by task kworker/u5:2/309

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= bf6a4e30ffbd9e9ef8934582feb937f6532f8b68 < e3880b531b68f98d3941d83f2f6dd11cf4fd6b76e3880b531b68f98d3941d83f2f6dd11cf4fd6b76
linuxlinux>= bf6a4e30ffbd9e9ef8934582feb937f6532f8b68 < a85a60e62355e3bf4802dead7938966824b23940a85a60e62355e3bf4802dead7938966824b23940
linuxlinux>= bf6a4e30ffbd9e9ef8934582feb937f6532f8b68 < 4f1de02de07748da80a8178879bc7a1df37fdf564f1de02de07748da80a8178879bc7a1df37fdf56
linuxlinux>= bf6a4e30ffbd9e9ef8934582feb937f6532f8b68 < 10f9f426ac6e752c8d87bf4346930ba347aaabac10f9f426ac6e752c8d87bf4346930ba347aaabac
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.12 < 6.1.916.1.91
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.