CVE-2024-35965 is a Linux kernel vulnerability affecting the Bluetooth L2CAP component, specifically an input validation flaw when processing setsockopt user input. This high-severity vulnerability (CVSS 7.1) allows a local, low-privileged attacker to achieve high confidentiality and availability impacts with low attack complexity. There is currently no public exploit code available, it is not listed in the KEV catalog, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.39, < 5.10.227CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 6.1.87CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.55CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.8.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025kernel: Bluetooth: L2CAP: Fix not validating setsockopt user input
May 20, 2024Bluetooth: L2CAP: Fix not validating setsockopt user input
May 14, 2024