cbcvebase.
CVE-2024-53237
published 2024-12-27

CVE-2024-53237: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix use-after-free in device_for_each_child() Syzbot has reported the following…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix use-after-free in device_for_each_child() Syzbot has reported the following KASAN splat: BUG: KASAN: slab-use-after-free in device_for_each_child+0x18f/0x1a0 Read of size 8 at addr ffff88801f605308 by task kbnepd bnep0/4980 CPU: 0 UID: 0 PID: 4980 Comm: kbnepd bnep0 Not tainted 6.12.0-rc4-00161-gae90f6a6170d #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014 Call Trace: dump_stack_lvl+0x100/0x190 ? device_for_each_child+0x18f/0x1a0 print_report+0x13a/0x4cb ? __virt_addr_valid+0x5e/0x590 ? __phys_addr+0xc6/0x150 ? device_for_each_child+0x18f/0x1a0 kasan_report+0xda/0x110 ? device_for_each_child+0x18f/0x1a0 ? __pfx_dev_memalloc_noio+0x10/0x10 device_for_each_child+0x18f/0x1a0 ? __pfx_device_for_each_child+0x10/0x10 pm_runtime_set_memalloc_noio+0xf2/0x180 netdev_unregister_kobject+0x1ed/0x270 unregister_netdevice_many_notify+0x123c/0x1d80 ? __mutex_trylock_common+0xde/0x250 ? __pfx_unregister_netdevice_many_notify+0x10/0x10 ? trace_contention_end+0xe6/0x140 ? __mutex_lock+0x4e7/0x8f0 ? __pfx_lock_acquire.part.0+0x10/0x10 ? rcu_is_watching+0x12/0xc0 ? unregister_netdev+0x12/0x30 unregister_netdevice_queue+0x30d/0x3f0 ? __pfx_unregister_netdevice_queue+0x10/0x10 ? __pfx_down_write+0x10/0x10 unregister_netdev+0x1c/0x30 bnep_session+0x1fb3/0x2ab0 ? __pfx_bnep_session+0x10/0x10 ? __pfx_lock_release+0x10/0x10 ? __pfx_woken_wake_function+0x10/0x10 ? __kthread_parkme+0x132/0x200 ? __pfx_bnep_session+0x10/0x10 ? kthread+0x13a/0x370 ? __pfx_bnep_session+0x10/0x10 kthread+0x2b7/0x370 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x48/0x80 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 Allocated by task 4974: kasan_save_stack+0x30/0x50 kasan_save_track+0x14/0x30 __kasan_kmalloc+0xaa/0xb0 __kmalloc_noprof+0x1d1/0x440 hci_alloc_dev_priv+0x1d/0x2820 __vhci_create_device+0xef/0x7d0 vhci_write+0x2c7/0x480 vfs_write+0x6a0/0xfc0 ksys_write+0x12f/0x260 do_syscall

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3c4236f1b2a715e878a06599fa8b0cc21f165d28 < 6894717a1ea363c5a27010ba604f957c309d282d6894717a1ea363c5a27010ba604f957c309d282d
linuxlinux>= 4.19.300 < 4.204.20
linuxlinux>= 5.10.202 < 5.10.2315.10.231
linuxlinux>= 5.15.140 < 5.15.1745.15.174
linuxlinux>= 5.4.262 < 5.4.2975.4.297
linuxlinux>= 53d61daf35b1bbf3ae06e852ee107aa2f05b3776 < fb91ce37dc9a37ea23cf32b6d7b667004e93d4c5fb91ce37dc9a37ea23cf32b6d7b667004e93d4c5
linuxlinux>= 56a4fdde95ed98d864611155f6728983e199e198 < de5a44f351ca7efd9add9851b218f5353e2224b7de5a44f351ca7efd9add9851b218f5353e2224b7
linuxlinux>= 6.1.64 < 6.1.1206.1.120
linuxlinux>= 6.5.13 < 6.66.6
linuxlinux>= 6.6.3 < 6.6.646.6.64
linuxlinux>= 87624b1f9b781549e69f92db7ede012a21cec275 < 0f67ca2a80acf8b207240405b7f72d660665d3df0f67ca2a80acf8b207240405b7f72d660665d3df
linuxlinux>= a85fb91e3d728bdfc80833167e8162cce8bc7004 < 91e2a2e4d1336333804cd31162984f01ad8cc70f91e2a2e4d1336333804cd31162984f01ad8cc70f
linuxlinux>= a85fb91e3d728bdfc80833167e8162cce8bc7004 < 7b277bd569bb6a2777f0014f84b4344f444fd49d7b277bd569bb6a2777f0014f84b4344f444fd49d
linuxlinux>= a85fb91e3d728bdfc80833167e8162cce8bc7004 < 27aabf27fd014ae037cc179c61b0bee7cff55b3d27aabf27fd014ae037cc179c61b0bee7cff55b3d
linuxlinux>= ba7088769800d9892a7e4f35c3137a5b3e65410b < a9584c897d1cba6265c78010bbb45ca5722c88bca9584c897d1cba6265c78010bbb45ca5722c88bc
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-214.2345.4.0-214.234

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.