5.5

CVE-2024-53144

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE

This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4
("Bluetooth: Always request for user confirmation for Just Works")
always request user confirmation with confirm_hint set since the
likes of bluetoothd have dedicated policy around JUST_WORKS method
(e.g. main.conf:JustWorksRepairing).

CVE: CVE-2024-8805
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login Login
Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 3.2.61 < 3.3
LinuxLinux Kernel Version >= 3.4.98 < 3.5
LinuxLinux Kernel Version >= 3.10.48 < 3.11
LinuxLinux Kernel Version >= 3.12.25 < 3.13
LinuxLinux Kernel Version >= 3.14.12 < 3.15
LinuxLinux Kernel Version >= 3.15.5 < 3.16
LinuxLinux Kernel Version >= 3.16.1 < 5.10.236
LinuxLinux Kernel Version >= 5.11 < 5.15.180
LinuxLinux Kernel Version >= 5.16 < 6.1.113
LinuxLinux Kernel Version >= 6.2 < 6.6.55
LinuxLinux Kernel Version >= 6.7 < 6.10.14
LinuxLinux Kernel Version >= 6.11 < 6.11.3
LinuxLinux Kernel Version3.16 Update-
LinuxLinux Kernel Version3.16 Updaterc3
LinuxLinux Kernel Version3.16 Updaterc4
LinuxLinux Kernel Version3.16 Updaterc5
LinuxLinux Kernel Version3.16 Updaterc6
LinuxLinux Kernel Version3.16 Updaterc7
LinuxLinux Kernel Version6.12 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.09
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H