Review reviewHigh

CVE-2024-53237

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix use-after-free in device_for_each_child() Syzbot has reported the following KASAN splat: BUG: KASAN: slab-use-after-free in device_for_each_child+0x18f/0x1a0 Read of size 8 at addr ffff88801f605308 by task kbnepd bnep0/4980 CPU: 0 UID: 0 PID: 4980 Comm: kbnepd bnep0 Not tainted 6.12.0-rc4-00161-gae90f6a6170d #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0x100/0x190 ? device_for_each_child+0x18f/0x1a0 print_report+0x13a/0x4cb ? __virt_...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.12.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix use-after-free in device_for_each_child() Syzbot has reported the following KASAN splat: BUG: KASAN: slab-use-after-free in device_for_each_child+0x18f/0x1a0 Read of size 8 at addr ffff88801f605308 by task kbnepd bnep0/4980 CPU: 0 UID: 0 PID: 4980 Comm: kbnepd bnep0 Not tainted 6.12.0-rc4-00161-gae90f6a6170d #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0x100/0x190 ? device_for_each_child+0x18f/0x1a0 print_report+0x13a/0x4cb ? __virt_...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 3c4236f1b2a715e878a06599fa8b0cc21f165d28 < 6894717a1ea363c5a27010ba604f957c309d282d, >= 53d61daf35b1bbf3ae06e852ee107aa2f05b3776 < fb91ce37dc9a37ea23cf32b6d7b667004e93d4c5, >= ba7088769800d9892a7e4f35c3137a5b3e65410b < a9584c897d1cba6265c78010bbb45ca5722c88bc, >= 87624b1f9b781549e69f92db7ede012a21cec275 < 0f67ca2a80acf8b207240405b7f72d660665d3df, >= 56a4fdde95ed98d864611155f6728983e199e198 < de5a44f351ca7efd9add9851b218f5353e2224b7, >= a85fb91e3d728bdfc80833167e8162cce8bc7004 < 91e2a2e4d1336333804cd31162984f01ad8cc70f, >= a85fb91e3d728bdfc80833167e8162cce8bc7004 < 7b277bd569bb6a2777f0014f84b4344f444fd49d, >= a85fb91e3d728bdfc80833167e8162cce8bc7004 < 27aabf27fd014ae037cc179c61b0bee7cff55b3d, >= 5c53afc766e07098429520b7677eaa164b593451, >= fc666d1b47518a18519241cae213de1babd4a4ba, >= 5.4.262 < 5.4.297, >= 5.10.202 < 5.10.231, >= 5.15.140 < 5.15.174, >= 6.1.64 < 6.1.120, >= 6.6.3 < 6.6.64, >= 4.19.300 < 4.20, >= 6.5.13 < 6.6, >= 6.7, >= 5.4.262 < 5.5, >= 6.7 < 6.11.11
Fixed versions
4.20, 5.5, 5.10.231, 5.15.174, 6.1.120, 6.6, 6.6.64, 6.11.11, 6.12.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2024-53237 — Linux Linux, linux kernel | SECUFOCUS NOW