cbcvebase.
CVE-2024-58009
published 2025-02-27

CVE-2024-58009: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc A NULL sock pointer is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc A NULL sock pointer is passed into l2cap_sock_alloc() when it is called from l2cap_sock_new_connection_cb() and the error handling paths should also be aware of it. Seemingly a more elegant solution would be to swap bt_sock_alloc() and l2cap_chan_create() calls since they are not interdependent to that moment but then l2cap_chan_create() adds the soon to be deallocated and still dummy-initialized channel to the global list accessible by many L2CAP paths. The channel would be removed from the list in short period of time but be a bit more straight-forward here and just check for NULL instead of changing the order of function calls. Found by Linux Verification Center (linuxtesting.org) with SVACE static analysis tool.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 5.10.231 < 5.10.2355.10.235
linuxlinux>= 5.15.174 < 5.15.1795.15.179
linuxlinux>= 5.4.287 < 5.4.2915.4.291
linuxlinux>= 6.1.120 < 6.1.1296.1.129
linuxlinux>= 6.12.5 < 6.12.146.12.14
linuxlinux>= 6.6.66 < 6.6.786.6.78
linuxlinux>= 61686abc2f3c2c67822aa23ce6f160467ec83d35 < 691218a50c3139f7f57ffa79fb89d932eda9571e691218a50c3139f7f57ffa79fb89d932eda9571e
linuxlinux>= 7c4f78cdb8e7501e9f92d291a7d956591bf73be9 < 49c0d55d59662430f1829ae85b969619573d0fa149c0d55d59662430f1829ae85b969619573d0fa1
linuxlinux>= 7c4f78cdb8e7501e9f92d291a7d956591bf73be9 < 5f397409f8ee5bc82901eeaf799e1cbc4f8edcf15f397409f8ee5bc82901eeaf799e1cbc4f8edcf1
linuxlinux>= 8ad09ddc63ace3950ac43db6fbfe25b40f589dd6 < 245d48c1ba3e7a1779c2f4cbc6f581ddc8a78e22245d48c1ba3e7a1779c2f4cbc6f581ddc8a78e22
linuxlinux>= a8677028dd5123e5e525b8195483994d87123de4 < cf601a24120c674cd7c907ea695f92617af6abd0cf601a24120c674cd7c907ea695f92617af6abd0
linuxlinux>= bb2f2342a6ddf7c04f9aefbbfe86104cd138e629 < 297ce7f544aa675b0d136d788cad0710cdfb0785297ce7f544aa675b0d136d788cad0710cdfb0785
linuxlinux>= daa13175a6dea312a76099066cb4cbd4fc959a84 < 8e605f580a97530e5a3583beea458a3fa4cbefbd8e605f580a97530e5a3583beea458a3fa4cbefbd
linuxlinux>= f6ad641646b67f29c7578dcd6c25813c7dcbf51e < a9a7672fc1a0fe18502493936ccb06413ab89ea6a9a7672fc1a0fe18502493936ccb06413ab89ea6
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 5.10.231 < 5.10.2355.10.235
linuxlinux_kernel>= 5.15.174 < 5.15.1795.15.179

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.