CVE-2024-35967

Source
https://cve.org/CVERecord?id=CVE-2024-35967
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35967.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35967
Downstream
Related
Published
2024-05-20T09:41:56.503Z
Modified
2026-05-28T03:52:42.934739639Z
Summary
Bluetooth: SCO: Fix not validating setsockopt user input
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: Fix not validating setsockopt user input

syzbot reported scosocksetsockopt() is copying data without checking user input length.

BUG: KASAN: slab-out-of-bounds in copyfromsockptroffset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copyfromsockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in scosock_setsockopt+0xc0b/0xf90 net/bluetooth/sco.c:893 Read of size 4 at addr ffff88805f7b15a3 by task syz-executor.5/12578

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35967.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b96e9c671b05f95126753a22145d4509d45ca197
Fixed
b0e30c37695b614bee69187f86eaf250e36606ce
Fixed
2c2dc87cdebef3fe3b9d7a711a984c70e376e32e
Fixed
7bc65d23ba20dcd7ecc094a12c181e594e5eb315
Fixed
72473db90900da970a16ee50ad23c2c38d107d8c
Fixed
419a0ffca7010216f0fc265b08558d7394fa0ba7
Fixed
51eda36d33e43201e7a4fd35232e069b2c850b01

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35967.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8.0
Fixed
5.10.216
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.178
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.87
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.28
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.8.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35967.json"