SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-22099

NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers.

MEDIUM 5.5EPSS 0.61%

Does this matter?

Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.

Description

NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12-rc2.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.61% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
linux/linux kernel
Source
security@openanolis.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.