7.1

CVE-2024-35964

Bluetooth: ISO: Fix not validating setsockopt user input

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: Fix not validating setsockopt user input

Check user input length before copying data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.0 < 6.1.119
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.55
Linux ≫ Linux Kernel Version >= 6.7 < 6.8.7
Linux ≫ Linux Kernel Version 6.9 Update rc1
Linux ≫ Linux Kernel Version 6.9 Update rc2
Linux ≫ Linux Kernel Version 6.9 Update rc3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.16
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE-1284 Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

https://git.kernel.org/stable/c/0c4a89f4690478969729c7ba5f69d53d8516aa12
Patch
https://git.kernel.org/stable/c/6a6baa1ee7a9df33adbf932305053520b9741b35
Patch
https://git.kernel.org/stable/c/9e8742cdfc4b0e65266bb4a901a19462bda9285e
Patch
https://git.kernel.org/stable/c/cec736e60dc18d91b88af28d96664bff284b02d1
Patch
https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html