THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-50029 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync This checks if the ACL connection remains valid as it could be destroyed while hci_enhanced_setup_sync is pending on cmd_sync leading to the following tra

[NVD] CVE-2024-50029 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync This checks if the ACL connection remains valid as it could be destroyed while hci_enhanced_setup_sync is pending on cmd_sync leading to the following tra

lownvdPublished 2024-10-21

CVE-2024-50029 CVSS: 8.8 HIGH Published: 2024-10-21T20:15:16.227

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync

This checks if the ACL connection remains valid as it could be destroyed while hci_enhanced_setup_sync is pending on cmd_sync leading to the following trace:

BUG: KASAN: slab-use-after-free in hci_enhanced_s

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-50029