A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3841-1 | linux-5.10 security update |
EUVD |
EUVD-2024-22223 | A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue. |
Ubuntu USN |
USN-6688-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6725-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6725-2 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-6818-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6818-2 | Linux kernel (ARM laptop) vulnerabilities |
Ubuntu USN |
USN-6818-3 | Linux kernel (NVIDIA) vulnerabilities |
Ubuntu USN |
USN-6818-4 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-6819-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6819-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6819-3 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6819-4 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-6972-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6972-2 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-6972-3 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6972-4 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-6973-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6973-2 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6973-3 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-6973-4 | Linux kernel (Raspberry Pi) vulnerabilities |
Ubuntu USN |
USN-7006-1 | Linux kernel vulnerabilities |
Fixes
Solution
https://github.com/torvalds/linux/commit/da9065caa594d https://github.com/torvalds/linux/commit/da9065caa594d
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue. | A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue. |
Status: PUBLISHED
Assigner: Anolis
Published:
Updated: 2025-02-13T17:40:34.429Z
Reserved: 2024-02-01T09:11:56.214Z
Link: CVE-2024-24860
Updated: 2024-08-01T23:28:12.994Z
Status : Modified
Published: 2024-02-05T08:15:45.077
Modified: 2025-02-13T18:17:10.967
Link: CVE-2024-24860
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN