CVE-2024-49951Use After Free in Linux

CWE-416Use After Free33 documents6 sources
Severity
5.5MEDIUMNVD
OSV8.8
EPSS
0.0%
top 99.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateApr 1

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix possible crash on mgmt_index_removed If mgmt_index_removed is called while there are commands queued on cmd_sync it could lead to crashes like the bellow trace: 0x0000053D: __list_del_entry_valid_or_report+0x98/0xdc 0x0000053D: mgmt_pending_remove+0x18/0x58 [bluetooth] 0x0000053E: mgmt_remove_adv_monitor_complete+0x80/0x108 [bluetooth] 0x0000053E: hci_cmd_sync_work+0xbc/0x164 [bluetooth] So while handlin

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel6.06.6.55+3
Debianlinux/linux_kernel< 6.1.123-1+2
Ubuntulinux/linux_kernel< 6.8.0-54.56+1
CVEListV5linux/linux7cf5c2978f23fdbb2dd7b4e8b07e362ae2d8211c19b40ca62607cef78369549d1af091f2fd558931+5
debiandebian/linux< linux 6.1.123-1 (bookworm)

Patches

🔴Vulnerability Details

16
OSV
linux-azure-6.8 vulnerabilities2025-04-01
OSV
linux-hwe-6.8 vulnerabilities2025-04-01
OSV
linux-azure vulnerabilities2025-03-27
OSV
linux-oem-6.8 vulnerabilities2025-03-27
OSV
linux-ibm vulnerabilities2025-03-27

📋Vendor Advisories

16
Ubuntu
Linux kernel (Azure) vulnerabilities2025-04-01
Ubuntu
Linux kernel (HWE) vulnerabilities2025-04-01
Ubuntu
Linux kernel (IBM) vulnerabilities2025-03-27
Ubuntu
Linux kernel (Azure) vulnerabilities2025-03-27
Ubuntu
Linux kernel (OEM) vulnerabilities2025-03-27