VDB

CISA-2024-36880

CISA-2024-36880 PUBLISHED

Reported by Linux · Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: add missing firmware sanity checks Add the missing sanity checks when parsing the firmware files before downloading them to avoid accessing and corrupting memory beyond the vmalloced buffer.

Affected Products

VendorProductVersions
LinuxLinux83e81961ff7ef75f97756f316caea5aa6bcc19cc, 83e81961ff7ef75f97756f316caea5aa6bcc19cc, 83e81961ff7ef75f97756f316caea5aa6bcc19cc
LinuxLinux4.3, 0, 5.15.159
LinuxLinux83e81961ff7ef75f97756f316caea5aa6bcc19cc, 83e81961ff7ef75f97756f316caea5aa6bcc19cc, 83e81961ff7ef75f97756f316caea5aa6bcc19cc

Timeline

  • May 30, 2024 CVE Published
  • Dec 19, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›