CVE-2024-26889

Source
https://cve.org/CVERecord?id=CVE-2024-26889
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26889.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26889
Downstream
Related
Published
2024-04-17T10:27:42.814Z
Modified
2026-03-20T12:35:17.484500Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Bluetooth: hci_core: Fix possible buffer overflow
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_core: Fix possible buffer overflow

struct hcidevinfo has a fixed size name[8] field so in the event that hdev->name is bigger than that strcpy would attempt to write past its size, so this fixes this problem by switching to use strscpy.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26889.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
194ab82c1ea187512ff2f822124bd05b63fc9f76
Fixed
6d5a9d4a7bcbb7534ce45a18a52e7bd23e69d8ac
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b48595f5b1c6e81e06e164e7d2b7a30b1776161e
Fixed
54a03e4ac1a41edf8a5087bd59f8241b0de96d3d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ffb060b136dd75a033ced0fc0aed2882c02e8b56
Fixed
d47e6c1932cee02954ea588c9f09fd5ecefeadfc
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bbec1724519ecd9c468d1186a8f30b7567175bfb
Fixed
2e845867b4e279eff0a19ade253390470e07e8a1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dcda165706b9fbfd685898d46a6749d7d397e0c0
Fixed
a41c8efe659caed0e21422876bbb6b73c15b5244
Fixed
8c28598a2c29201d2ba7fc37539a7d41c264fb10
Fixed
2edce8e9a99dd5e4404259d52e754fdc97fb42c2
Fixed
81137162bfaa7278785b24c1fd2e9e74f082e8e4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
d9ce7d438366431e5688be98d8680336ce0a0f8d
Last affected
a55d53ad5c86aee3f6da50ee73626008997673fa
Last affected
5558f4312dca43cebfb9a1aab3d632be91bbb736

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26889.json"