CVE-2024-26801

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
04/04/2024
Last modified:
20/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: Avoid potential use-after-free in hci_error_reset<br /> <br /> While handling the HCI_EV_HARDWARE_ERROR event, if the underlying<br /> BT controller is not responding, the GPIO reset mechanism would<br /> free the hci_dev and lead to a use-after-free in hci_error_reset.<br /> <br /> Here&amp;#39;s the call trace observed on a ChromeOS device with Intel AX201:<br /> queue_work_on+0x3e/0x6c<br /> __hci_cmd_sync_sk+0x2ee/0x4c0 [bluetooth ]<br /> ? init_wait_entry+0x31/0x31<br /> __hci_cmd_sync+0x16/0x20 [bluetooth ]<br /> hci_error_reset+0x4f/0xa4 [bluetooth ]<br /> process_one_work+0x1d8/0x33f<br /> worker_thread+0x21b/0x373<br /> kthread+0x13a/0x152<br /> ? pr_cont_work+0x54/0x54<br /> ? kthread_blkcg+0x31/0x31<br /> ret_from_fork+0x1f/0x30<br /> <br /> This patch holds the reference count on the hci_dev while processing<br /> a HCI_EV_HARDWARE_ERROR event to avoid potential crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.0 (including) 4.19.309 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.271 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.212 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.151 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.81 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.21 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.9 (excluding)
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:*