Back

HIGH

Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet

Published Dec 27, 2024

Description

This fixes not checking if skb really contains an ACL header otherwise the code may attempt to access some uninitilized/invalid memory past the valid skb->data.

Affected products

Remediation

Red Hat statement

This vulnerability, rated as moderate severity, involves a flaw in the Linux kernel's Bluetooth subsystem. A failure to validate the socket buffer's length before accessing ACL headers can lead to out-of-bounds memory access. This creates a risk of kernel memory corruption, potentially allowing attackers to corrupt kernel memory related to bluetooth networking, which might impact the functionality of connected devices. However, even in situations where an attacker had significant access to and information about a target system, our assessment indicates that the security features of the kernel would prevent a compromise of confidentiality or the ability to escalate their privileges.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 27, 2024
Updated Aug 5, 2026
Reserved Dec 27, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Dec 27, 2024