CVE-2024-57879

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: iso: Always release hdev at the end of iso_listen_bis Since hci_get_route holds the device before returning, the hdev should be released with hci_dev_put at the end of iso_listen_bis even if the function returns with an error.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:*

History

17 Oct 2025, 15:30

Type Values Removed Values Added
CWE CWE-404
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: Bluetooth: iso: Siempre liberar hdev al final de iso_listen_bis Dado que hci_get_route retiene el dispositivo antes de regresar, el hdev debe liberarse con hci_dev_put al final de iso_listen_bis incluso si la función regresa con un error.
References () https://git.kernel.org/stable/c/4ca50db1c567d658d173c5ef3ee6c52b0b03603c - () https://git.kernel.org/stable/c/4ca50db1c567d658d173c5ef3ee6c52b0b03603c - Patch
References () https://git.kernel.org/stable/c/9c76fff747a73ba01d1d87ed53dd9c00cb40ba05 - () https://git.kernel.org/stable/c/9c76fff747a73ba01d1d87ed53dd9c00cb40ba05 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:*

11 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 15:15

Updated : 2025-10-17 15:30


NVD link : CVE-2024-57879

Mitre link : CVE-2024-57879

CVE.ORG link : CVE-2024-57879


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-404

Improper Resource Shutdown or Release