In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Ignore too large handle values in BIG
hcilebigsyncestablishedevt is necessary to filter out cases where the handle value is belonging to ida id range, otherwise ida will be erroneously released in hciconn_cleanup.
[
{
"id": "CVE-2024-42133-25337c6d",
"signature_type": "Line",
"digest": {
"line_hashes": [
"223335221450571761227888538569546648644",
"81686452431966846106161797854668090566",
"141581481184983844476001648632398159040",
"289071807985758303825965936304348051166"
],
"threshold": 0.9
},
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@38263088b845abeeeb98dda5b87c0de3063b6dbb",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2024-42133-39fbb064",
"signature_type": "Function",
"digest": {
"length": 1405.0,
"function_hash": "322865427862381921216062350573072462610"
},
"target": {
"function": "hci_le_big_sync_established_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dad0003ccc68457baf005a6ed75b4d321463fe3d",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2024-42133-3dd530c3",
"signature_type": "Line",
"digest": {
"line_hashes": [
"223335221450571761227888538569546648644",
"81686452431966846106161797854668090566",
"141581481184983844476001648632398159040",
"289071807985758303825965936304348051166"
],
"threshold": 0.9
},
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@015d79c96d62cd8a4a359fcf5be40d58088c936b",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2024-42133-7cce20fd",
"signature_type": "Line",
"digest": {
"line_hashes": [
"223335221450571761227888538569546648644",
"81686452431966846106161797854668090566",
"141581481184983844476001648632398159040",
"289071807985758303825965936304348051166"
],
"threshold": 0.9
},
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dad0003ccc68457baf005a6ed75b4d321463fe3d",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2024-42133-9cd8e116",
"signature_type": "Function",
"digest": {
"length": 1547.0,
"function_hash": "223460830905529844977215478732357970413"
},
"target": {
"function": "hci_le_big_sync_established_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@38263088b845abeeeb98dda5b87c0de3063b6dbb",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2024-42133-b538086f",
"signature_type": "Function",
"digest": {
"length": 1405.0,
"function_hash": "322865427862381921216062350573072462610"
},
"target": {
"function": "hci_le_big_sync_established_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@015d79c96d62cd8a4a359fcf5be40d58088c936b",
"signature_version": "v1",
"deprecated": false
}
]