Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-42132— bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX

CVSS 7.6 · High EPSS 0.29% · P21

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxf7e83f2278f06b577e3c92ea2f4e8e8c6fc72a8f< 2ae8d7742a09c275872e670c53337b3dcedaa11caffected
84cb0143fb8a03bf941c7aaedd56c938c99dafad< 4970e48f83dbd21d2a6a7cdaaafc2a71f7f45dc4affected
181a42edddf51d5d9697ecdf365d72ebeab5afb0< d311036696fed778301d08a71a4bef737b86d8c5affected
181a42edddf51d5d9697ecdf365d72ebeab5afb0< 1cc18c2ab2e8c54c355ea7c0423a636e415a0c23affected
e9f708beada55426c8d678e2f46af659eb5bf4f0affected
6.6.2< 6.6.39affected
6.5.12< 6.6affected
6.7affected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-42132

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caused by handle bigger than HCI_CONN_HANDLE_MAX passed by hci_le_big_sync_established_evt(), which makes code think it's unset connection. Add same check for handle upper bound as in hci_conn_set_handle() to prevent warning.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于Bluetooth/hci模块中允许设置大于HCI_CONN_HANDLE_MAX的handle值,导致未分配的handle被错误地释放。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f7e83f2278f06b577e3c92ea2f4e8e8c6fc72a8f ~ 2ae8d7742a09c275872e670c53337b3dcedaa11c -
LinuxLinux 6.7 -

II. Public POCs for CVE-2024-42132

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-42132

登录查看更多情报信息。

Other References for CVE-2024-42132 (3)

Same Patch Batch · Linux · 2024-07-30 · 70 CVEs total

CVE-2024-421089.8 CRITICALnet: rswitch: Avoid use-after-free in rswitch_poll()
CVE-2024-422258.3 HIGHwifi: mt76: replace skb_put with skb_put_zero
CVE-2024-421177.8 HIGHdrm/amd/display: ASSERT when failing to find index by plane/stream id
CVE-2024-421207.8 HIGHdrm/amd/display: Check pipe offset before setting vblank
CVE-2024-421037.8 HIGHbtrfs: fix adding block group to a reclaim list and the unused list during reclaim
CVE-2024-420997.8 HIGHs390/dasd: Fix invalid dereferencing of indirect CCW data pointer
CVE-2024-421047.8 HIGHnilfs2: add missing check for inode numbers on directory entries
CVE-2024-421057.8 HIGHnilfs2: fix inode number range checks
CVE-2024-421097.8 HIGHnetfilter: nf_tables: unconditionally flush pending work before notifier
CVE-2024-421117.8 HIGHbtrfs: always do the basic checks for btrfs_qgroup_inherit structure
CVE-2024-421127.8 HIGHnet: txgbe: free isb resources at the right time
CVE-2024-421157.8 HIGHjffs2: Fix potential illegal address access in jffs2_free_inode
CVE-2024-421627.8 HIGHgve: Account for stopped queues when reading NIC stats
CVE-2024-421337.6 HIGHBluetooth: Ignore too large handle values in BIG
CVE-2024-421527.5 HIGHnvmet: fix a possible leak when destroy a ctrl during qp establishment
CVE-2024-421457.5 HIGHIB/core: Implement a limit on UMAD receive List
CVE-2024-421107.5 HIGHnet: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx()
CVE-2024-421237.0 HIGHdrm/amdgpu: fix double free err_addr pointer warnings
CVE-2024-422247.0 HIGHnet: dsa: mv88e6xxx: Correct check for empty list
CVE-2024-42151bpf: mark bpf_dummy_struct_ops.test_1 parameter as nullable

Showing top 20 of 70 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-42132

No comments yet


Leave a comment