CVE-2024-26801

Source
https://cve.org/CVERecord?id=CVE-2024-26801
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26801.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26801
Downstream
Related
Published
2024-04-04T08:20:29.211Z
Modified
2026-05-28T03:54:47.935665730Z
Summary
Bluetooth: Avoid potential use-after-free in hci_error_reset
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: Avoid potential use-after-free in hcierrorreset

While handling the HCIEVHARDWAREERROR event, if the underlying BT controller is not responding, the GPIO reset mechanism would free the hcidev and lead to a use-after-free in hcierrorreset.

Here's the call trace observed on a ChromeOS device with Intel AX201: queueworkon+0x3e/0x6c __hcicmdsync_sk+0x2ee/0x4c0 [bluetooth <HASH:3b4a6>] ? initwaitentry+0x31/0x31 __hcicmdsync+0x16/0x20 [bluetooth <HASH:3b4a 6>] hcierrorreset+0x4f/0xa4 [bluetooth <HASH:3b4a 6>] processonework+0x1d8/0x33f workerthread+0x21b/0x373 kthread+0x13a/0x152 ? prcontwork+0x54/0x54 ? kthreadblkcg+0x31/0x31 retfromfork+0x1f/0x30

This patch holds the reference count on the hcidev while processing a HCIEVHARDWAREERROR event to avoid potential crash.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26801.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c7741d16a57cbf97eebe53f27e8216b1ff20e20c
Fixed
e0b278650f07acf2e0932149183458468a731c03
Fixed
98fb98fd37e42fd4ce13ff657ea64503e24b6090
Fixed
6dd0a9dfa99f8990a08eb8fdd8e79bee31c7d8e2
Fixed
da4569d450b193e39e87119fd316c0291b585d14
Fixed
45085686b9559bfbe3a4f41d3d695a520668f5e1
Fixed
2ab9a19d896f5a0dd386e1f001c5309bc35f433b
Fixed
dd594cdc24f2e48dab441732e6dfcafd6b0711d1
Fixed
2449007d3f73b2842c9734f45f0aadb522daf592

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26801.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.19.309
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.271
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.212
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.151
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.81
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.21
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26801.json"