Review reviewHigh

CVE-2024-42132

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caused by handle bigger than HCI_CONN_HANDLE_MAX passed by hci_le_big_sync_established_evt(), which makes code think it's unset connection. Add same check for handle upper bound as in hci_conn_set_handle() to prevent warning.

CVSS
7.1
EPSS
0.29%
21.1% percentile
CISA KEV
Not listed
Published
2024.07.30
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.29%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caused by handle bigger than HCI_CONN_HANDLE_MAX passed by hci_le_big_sync_established_evt(), which makes code think it's unset connection. Add same check for handle upper bound as in hci_conn_set_handle() to prevent warning.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= f7e83f2278f06b577e3c92ea2f4e8e8c6fc72a8f < 2ae8d7742a09c275872e670c53337b3dcedaa11c, >= 84cb0143fb8a03bf941c7aaedd56c938c99dafad < 4970e48f83dbd21d2a6a7cdaaafc2a71f7f45dc4, >= 181a42edddf51d5d9697ecdf365d72ebeab5afb0 < d311036696fed778301d08a71a4bef737b86d8c5, >= 181a42edddf51d5d9697ecdf365d72ebeab5afb0 < 1cc18c2ab2e8c54c355ea7c0423a636e415a0c23, >= e9f708beada55426c8d678e2f46af659eb5bf4f0, >= 6.6.2 < 6.6.39, >= 6.5.12 < 6.6, >= 6.7, >= 6.7 < 6.9.9, 6.10
Fixed versions
6.6, 6.6.39, 6.9.9

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CWE
CWE-763