CVE-2024-50125

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
05/11/2024
Last modified:
02/05/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: SCO: Fix UAF on sco_sock_timeout<br /> <br /> conn-&gt;sk maybe have been unlinked/freed while waiting for sco_conn_lock<br /> so this checks if the conn-&gt;sk is still valid by checking if it part of<br /> sco_sk_list.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15 (including) 6.1.115 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.59 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.11.6 (excluding)
cpe:2.3:o:linux:linux_kernel:4.14.263:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.19.207:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.4.148:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.10.67:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.14.6:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc4:*:*:*:*:*:*