CVE-2024-36880
Bluetooth: qca: add missing firmware sanity checks
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 May 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: qca: add missing firmware sanity checks
Add the missing sanity checks when parsing the firmware files before
downloading them to avoid accessing and corrupting memory beyond the
vmalloced buffer.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/02f05ed44b71152d5e11d29be28aed91c0489b4ehttps://git.kernel.org/stable/c/1caceadfb50432dbf6d808796cb6c34ebb6d662chttps://git.kernel.org/stable/c/2e4edfa1e2bd821a317e7d006517dcf2f3fac68dhttps://git.kernel.org/stable/c/427281f9498ed614f9aabc80e46ec077c487da6dhttps://git.kernel.org/stable/c/ed53949cc92e28aaa3463d246942bda1fbb7f307