cbcvebase.
CVE-2024-50125
published 2024-11-05

CVE-2024-50125: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix UAF on sco_sock_timeout conn->sk maybe have been unlinked/freed while…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix UAF on sco_sock_timeout conn->sk maybe have been unlinked/freed while waiting for sco_conn_lock so this checks if the conn->sk is still valid by checking if it part of sco_sk_list.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.263 < 4.154.15
linuxlinux>= 4.19.207 < 4.204.20
linuxlinux>= 5.10.67 < 5.115.11
linuxlinux>= 5.13.19 < 5.145.14
linuxlinux>= 5.14.6 < 5.155.15
linuxlinux>= 5.4.148 < 5.55.5
linuxlinux>= ba316be1b6a00db7126ed9a39f9bee434a508043 < 74a466a15731a754bcd8b5a83c126b5122e15a4574a466a15731a754bcd8b5a83c126b5122e15a45
linuxlinux>= ba316be1b6a00db7126ed9a39f9bee434a508043 < 9ddda5d967e84796e7df1b54a55f36b4b9f210799ddda5d967e84796e7df1b54a55f36b4b9f21079
linuxlinux>= ba316be1b6a00db7126ed9a39f9bee434a508043 < d30803f6a972b5b9e26d1d43b583c7ec151de04bd30803f6a972b5b9e26d1d43b583c7ec151de04b
linuxlinux>= ba316be1b6a00db7126ed9a39f9bee434a508043 < 80b05fbfa998480fb3d5299d93eab946f51e9c3680b05fbfa998480fb3d5299d93eab946f51e9c36
linuxlinux>= ba316be1b6a00db7126ed9a39f9bee434a508043 < 1bf4470a3939c678fb822073e9ea77a0560bc6bb1bf4470a3939c678fb822073e9ea77a0560bc6bb
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.