CVE-2024-24859
Race condition vulnerability in Linux kernel bluetooth sniff_{min,max}_interval_set()
Severity Score
4.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service.
Se encontró una condición de ejecución en la red/bluetooth del kernel de Linux en la función sniff_{min,max}_interval_set(). Esto puede provocar un problema de excepción de rastreo de Bluetooth, lo que posiblemente provoque una denegación de servicio.
A race condition vulnerability was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This issue can result in a Bluetooth sniffing exception issue, possibly leading to denial of service.
*Credits:
白家驹 <baijiaju@buaa.edu.cn>, 韩桂栋 <hanguidong@buaa.edu.cn>
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-02-01 CVE Reserved
- 2024-02-05 CVE Published
- 2024-02-10 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
- CAPEC-26: Leveraging Race Conditions
References (3)
URL | Tag | Source |
---|---|---|
https://bugzilla.openanolis.cn/show_bug.cgi?id=8153 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-24859 | 2024-11-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2298817 | 2024-11-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | <= 3.19.8 Search vendor "Linux" for product "Linux Kernel" and version " <= 3.19.8" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.0 <= 6.7.2 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.0 <= 6.7.2" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 6.8 Search vendor "Linux" for product "Linux Kernel" and version "6.8" | rc1 |
Affected
|