CVE-2024-36880
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: add missing firmware sanity checks Add the missing sanity checks when parsing the firmware files before downloading them to avoid accessing and corrupting memory beyond…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: add missing firmware sanity checks Add the missing sanity checks when parsing the firmware files before downloading them to avoid accessing and corrupting memory beyond the vmalloced buffer.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/02f05ed44b71152d5e11d29be28aed91c0489b4ePatch
- https://git.kernel.org/stable/c/1caceadfb50432dbf6d808796cb6c34ebb6d662cPatch
- https://git.kernel.org/stable/c/2e4edfa1e2bd821a317e7d006517dcf2f3fac68dPatch
- https://git.kernel.org/stable/c/427281f9498ed614f9aabc80e46ec077c487da6dPatch
- https://git.kernel.org/stable/c/ed53949cc92e28aaa3463d246942bda1fbb7f307Patch
- https://git.kernel.org/stable/c/02f05ed44b71152d5e11d29be28aed91c0489b4ePatch
- https://git.kernel.org/stable/c/1caceadfb50432dbf6d808796cb6c34ebb6d662cPatch
- https://git.kernel.org/stable/c/2e4edfa1e2bd821a317e7d006517dcf2f3fac68dPatch
- https://git.kernel.org/stable/c/427281f9498ed614f9aabc80e46ec077c487da6dPatch
- https://git.kernel.org/stable/c/ed53949cc92e28aaa3463d246942bda1fbb7f307Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.