CVE-2024-35978 is a memory leak vulnerability in the Linux kernel's Bluetooth component, specifically within the hci_req_sync_complete() function. This flaw, rated Medium with a CVSS score of 5.5, could lead to a denial-of-service condition due to memory exhaustion. While the vulnerability is present in Linux and its kernel, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1, < 4.19.313CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.275CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.216CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.156CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.87CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024CVE-2024-35978
Sep 10, 2024kernel: Bluetooth: Fix memory leak in hci_req_sync_complete()
May 20, 2024Bluetooth: Fix memory leak in hci_req_sync_complete()
May 14, 2024OVMSA-2024-0011: Unbreakable Enterprise kernel security update (IMPORTANT)