Bugzilla – Bug 1225721
VUL-0: CVE-2024-36033: kernel: Bluetooth: qca: fix info leak when fetching board id
Last modified: 2024-06-10 13:32:31 UTC
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching board id Add the missing sanity check when fetching the board id to avoid leaking slab data when later requesting the firmware. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-36033 https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-36033.mbox https://git.kernel.org/stable/c/bcccdc947d2ca5972b1e92d0dea10803ddc08ceb https://git.kernel.org/stable/c/ba307abed5e09759845c735ba036f8c12f55b209 https://git.kernel.org/stable/c/f30c37cb4549baf8377434892d520fe7769bdba7 https://git.kernel.org/stable/c/0adcf6be1445ed50bfd4a451a7a782568f270197 https://www.cve.org/CVERecord?id=CVE-2024-36033
All done, closing.