cbcvebase.
CVE-2024-53144
published 2024-12-17

CVE-2024-53144: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always request user confirmation with confirm_hint set since the likes of bluetoothd have dedicated policy around JUST_WORKS method (e.g. main.conf:JustWorksRepairing). CVE: CVE-2024-8805

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.10.48 < 3.113.11
linuxlinux>= 3.12.25 < 3.133.13
linuxlinux>= 3.14.12 < 3.153.15
linuxlinux>= 3.15.5 < 3.163.16
linuxlinux>= 3.2.61 < 3.33.3
linuxlinux>= 3.4.98 < 3.53.5
linuxlinux>= ba15a58b179ed76a7e887177f2b06de12c58ec8f < baaa50c6f91ea5a9c7503af51f2bc50e6568b66bbaaa50c6f91ea5a9c7503af51f2bc50e6568b66b
linuxlinux>= ba15a58b179ed76a7e887177f2b06de12c58ec8f < 22b49d6e4f399a390c70f3034f5fbacbb941385822b49d6e4f399a390c70f3034f5fbacbb9413858
linuxlinux>= ba15a58b179ed76a7e887177f2b06de12c58ec8f < d17c631ba04e960eb6f8728b10d585de20ac4f71d17c631ba04e960eb6f8728b10d585de20ac4f71
linuxlinux>= ba15a58b179ed76a7e887177f2b06de12c58ec8f < 830c03e58beb70b99349760f822e505ecb4eeb7e830c03e58beb70b99349760f822e505ecb4eeb7e
linuxlinux>= ba15a58b179ed76a7e887177f2b06de12c58ec8f < ad7adfb95f64a761e4784381e47bee1a362eb30dad7adfb95f64a761e4784381e47bee1a362eb30d
linuxlinux>= ba15a58b179ed76a7e887177f2b06de12c58ec8f < 5291ff856d2c5177b4fe9c18828312be302131935291ff856d2c5177b4fe9c18828312be30213193
linuxlinux>= ba15a58b179ed76a7e887177f2b06de12c58ec8f < b25e11f978b63cb7857890edb3a698599cddb10eb25e11f978b63cb7857890edb3a698599cddb10e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.