cbcvebase.
CVE-2024-36032
published 2024-05-30

CVE-2024-36032: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case the build-info reply is malformed.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 < 62d5550ab62042dcceaf18844d0feadbb962cffe62d5550ab62042dcceaf18844d0feadbb962cffe
linuxlinux>= c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 < 57062aa13e87b1a78a4a8f6cb5fab6ba24f5f48857062aa13e87b1a78a4a8f6cb5fab6ba24f5f488
linuxlinux>= c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 < 6b63e0ef4d3ce0080395e5091fba2023f246c45a6b63e0ef4d3ce0080395e5091fba2023f246c45a
linuxlinux>= c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 < a571044cc0a0c944e7c12237b6768aeedd7480e1a571044cc0a0c944e7c12237b6768aeedd7480e1
linuxlinux>= c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 < cda0d6a198e2a7ec6f176c36173a57bdd8af7af2cda0d6a198e2a7ec6f176c36173a57bdd8af7af2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.12 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.