cbcvebase.
CVE-2024-36033
published 2024-05-30

CVE-2024-36033: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching board id Add the missing sanity check when…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching board id Add the missing sanity check when fetching the board id to avoid leaking slab data when later requesting the firmware.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= a381ee26d7c70dbc048cd17c4e0f40619118ff1f < ba307abed5e09759845c735ba036f8c12f55b209ba307abed5e09759845c735ba036f8c12f55b209
linuxlinux>= a7f8dedb4be2cc930a29af24427b885405ecd15d < f30c37cb4549baf8377434892d520fe7769bdba7f30c37cb4549baf8377434892d520fe7769bdba7
linuxlinux>= a7f8dedb4be2cc930a29af24427b885405ecd15d < 0adcf6be1445ed50bfd4a451a7a782568f2701970adcf6be1445ed50bfd4a451a7a782568f270197
linuxlinux>= ad643241d455fdd2516d46cfa54bd0c5e504fc86 < bcccdc947d2ca5972b1e92d0dea10803ddc08cebbcccdc947d2ca5972b1e92d0dea10803ddc08ceb
linuxlinux>= c3c1bd421db6187ee455995bfbf1ba16d98f5e6b < a3dff121a7f5104c4c2d47edaa2351837ef645dda3dff121a7f5104c4c2d47edaa2351837ef645dd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
vendor_oracle6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.