CVE-2024-24857: Race condition vulnerability in Linux kernel bluetooth in conn_info_{min,max}_age_set()
A race condition was found in the Linux kernel's net/bluetooth device driver in conninfo{min,max}ageset() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24857?
CVE-2024-24857 has been classified with a medium severity due to the potential for integrity overflow issues.
How do I fix CVE-2024-24857?
To mitigate CVE-2024-24857, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.
Which versions of Linux are affected by CVE-2024-24857?
Linux kernel versions from 3.19.8 up to 6.8-rc1 are affected by CVE-2024-24857.
What are the potential impacts of CVE-2024-24857?
CVE-2024-24857 may lead to Bluetooth connection abnormalities or denial of service issues.
Is CVE-2024-24857 a race condition vulnerability?
Yes, CVE-2024-24857 is a race condition vulnerability that affects the Bluetooth device driver in the Linux kernel.