CVE-2024-35978

medium

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix memory leak in hci_req_sync_complete() In 'hci_req_sync_complete()', always free the previous sync request state before assigning reference to a new one.

References

https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html

https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html

https://git.kernel.org/stable/c/e4cb8382fff6706436b66eafd9c0ee857ff0a9f5

https://git.kernel.org/stable/c/e4cb8382fff6706436b66eafd9c0ee857ff0a9f5

https://git.kernel.org/stable/c/9ab5e44b9bac946bd49fd63264a08cd1ea494e76

https://git.kernel.org/stable/c/9ab5e44b9bac946bd49fd63264a08cd1ea494e76

https://git.kernel.org/stable/c/89a32741f4217856066c198a4a7267bcdd1edd67

https://git.kernel.org/stable/c/89a32741f4217856066c198a4a7267bcdd1edd67

https://git.kernel.org/stable/c/8478394f76c748862ef179a16f651f752bdafaf0

https://git.kernel.org/stable/c/8478394f76c748862ef179a16f651f752bdafaf0

https://git.kernel.org/stable/c/75193678cce993aa959e7764b6df2f599886dd06

https://git.kernel.org/stable/c/75193678cce993aa959e7764b6df2f599886dd06

https://git.kernel.org/stable/c/66fab1e120b39f8f47a94186ddee36006fc02ca8

https://git.kernel.org/stable/c/66fab1e120b39f8f47a94186ddee36006fc02ca8

https://git.kernel.org/stable/c/4beab84fbb50df3be1d8f8a976e6fe882ca65cb2

https://git.kernel.org/stable/c/4beab84fbb50df3be1d8f8a976e6fe882ca65cb2

https://git.kernel.org/stable/c/45d355a926ab40f3ae7bc0b0a00cb0e3e8a5a810

https://git.kernel.org/stable/c/45d355a926ab40f3ae7bc0b0a00cb0e3e8a5a810

Details

Source: Mitre, NVD

Published: 2024-05-20

Updated: 2024-06-27

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium