In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev setup Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. Add the missing sanity check to prevent a NULL-pointer dereference when setup() is called for a non-serdev controller.
History

Thu, 19 Sep 2024 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 11 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published: 2024-05-17T14:47:28.139Z

Updated: 2024-09-11T17:33:17.995Z

Reserved: 2024-05-17T13:50:33.105Z

Link: CVE-2024-35850

cve-icon Vulnrichment

Updated: 2024-08-02T03:21:48.528Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-17T15:15:21.860

Modified: 2024-05-17T18:35:35.070

Link: CVE-2024-35850

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-05-17T00:00:00Z

Links: CVE-2024-35850 - Bugzilla