In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcievent: Fix handling of HCIEVIOCAPA_REQUEST
If we received HCIEVIOCAPAREQUEST while HCIOPREADREMOTEEXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27416.json"
}[
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e2758cc25891d2b76717aaf89b40ed215de188c",
"digest": {
"function_hash": "261921581772865092562415592680263556218",
"length": 1325.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-135064a6"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@afec8f772296dd8e5a2a6f83bbf99db1b9ca877f",
"digest": {
"line_hashes": [
"95332731043457274065924381105572286028",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-1e594419"
},
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@30a5e812f78e3d1cced90e1ed750bf027599205f",
"digest": {
"function_hash": "261921581772865092562415592680263556218",
"length": 1325.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-22f68185"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865",
"digest": {
"line_hashes": [
"82450796303787425156360685424424340312",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-2caaa688"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c3df637266df29edee85e94cab5fd7041e5753ba",
"digest": {
"line_hashes": [
"95332731043457274065924381105572286028",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-3a92f3bf"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@30a5e812f78e3d1cced90e1ed750bf027599205f",
"digest": {
"line_hashes": [
"82450796303787425156360685424424340312",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-6003f9d4"
},
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865",
"digest": {
"function_hash": "261921581772865092562415592680263556218",
"length": 1325.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-7dd0b891"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e2758cc25891d2b76717aaf89b40ed215de188c",
"digest": {
"line_hashes": [
"82450796303787425156360685424424340312",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-83f35559"
},
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@afec8f772296dd8e5a2a6f83bbf99db1b9ca877f",
"digest": {
"function_hash": "108704730272158560402736352936545704255",
"length": 1339.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-ac5fc639"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fba268ac36ab19f9763ff90d276cde0ce6cd5f31",
"digest": {
"line_hashes": [
"82450796303787425156360685424424340312",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-b29c44ec"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@79820a7e1e057120c49be07cbe10643d0706b259",
"digest": {
"line_hashes": [
"95332731043457274065924381105572286028",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-bce0b071"
},
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fba268ac36ab19f9763ff90d276cde0ce6cd5f31",
"digest": {
"function_hash": "261921581772865092562415592680263556218",
"length": 1325.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-c02d272b"
},
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c3df637266df29edee85e94cab5fd7041e5753ba",
"digest": {
"function_hash": "108704730272158560402736352936545704255",
"length": 1339.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-c12c9cdb"
},
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@79820a7e1e057120c49be07cbe10643d0706b259",
"digest": {
"function_hash": "108704730272158560402736352936545704255",
"length": 1339.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-c2bd84b8"
},
{
"deprecated": false,
"target": {
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@df193568d61234c81de7ed4d540c01975de60277",
"digest": {
"line_hashes": [
"95332731043457274065924381105572286028",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2024-27416-d7130b80"
},
{
"deprecated": false,
"target": {
"function": "hci_io_capa_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@df193568d61234c81de7ed4d540c01975de60277",
"digest": {
"function_hash": "108704730272158560402736352936545704255",
"length": 1339.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2024-27416-fce02e09"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-27416.json"