CVE-2024-53238

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-53238
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-53238.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-53238
Downstream
Related
Published
2024-12-27T13:50:24Z
Modified
2025-10-10T02:22:50.492530Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Bluetooth: btmtk: adjust the position to init iso data anchor
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btmtk: adjust the position to init iso data anchor

MediaTek iso data anchor init should be moved to where MediaTek claims iso data interface. If there is an unexpected BT usb disconnect during setup flow, it will cause a NULL pointer crash issue when releasing iso anchor since the anchor wasn't been init yet. Adjust the position to do iso data anchor init.

[ 17.137991] pc : usbkillanchoredurbs+0x60/0x168 [ 17.137998] lr : usbkillanchoredurbs+0x44/0x168 [ 17.137999] sp : ffffffc0890cb5f0 [ 17.138000] x29: ffffffc0890cb5f0 x28: ffffff80bb6c2e80 [ 17.144081] gpio gpiochip0: registered chardev handle for 1 lines [ 17.148421] x27: 0000000000000000 [ 17.148422] x26: ffffffd301ff4298 x25: 0000000000000003 x24: 00000000000000f0 [ 17.148424] x23: 0000000000000000 x22: 00000000ffffffff x21: 0000000000000001 [ 17.148425] x20: ffffffffffffffd8 x19: ffffff80c0f25560 x18: 0000000000000000 [ 17.148427] x17: ffffffd33864e408 x16: ffffffd33808f7c8 x15: 0000000000200000 [ 17.232789] x14: e0cd73cf80ffffff x13: 50f2137c0a0338c9 x12: 0000000000000001 [ 17.239912] x11: 0000000080150011 x10: 0000000000000002 x9 : 0000000000000001 [ 17.247035] x8 : 0000000000000000 x7 : 0000000000008080 x6 : 8080000000000000 [ 17.254158] x5 : ffffffd33808ebc0 x4 : fffffffe033dcf20 x3 : 0000000080150011 [ 17.261281] x2 : ffffff8087a91400 x1 : 0000000000000000 x0 : ffffff80c0f25588 [ 17.268404] Call trace: [ 17.270841] usbkillanchoredurbs+0x60/0x168 [ 17.275274] btusbmtkreleaseisointf+0x2c/0xd8 [btusb (HASH:5afe 6)] [ 17.284226] btusbmtkdisconnect+0x14/0x28 [btusb (HASH:5afe 6)] [ 17.292652] btusbdisconnect+0x70/0x140 [btusb (HASH:5afe 6)] [ 17.300818] usbunbindinterface+0xc4/0x240 [ 17.305079] devicereleasedriverinternal+0x18c/0x258 [ 17.310296] devicereleasedriver+0x1c/0x30 [ 17.314557] busremovedevice+0x140/0x160 [ 17.318643] devicedel+0x1c0/0x330 [ 17.322121] usbdisabledevice+0x80/0x180 [ 17.326207] usbdisconnect+0xec/0x300 [ 17.329948] hubquiesce+0x80/0xd0 [ 17.333339] hubdisconnect+0x44/0x190 [ 17.337078] usbunbindinterface+0xc4/0x240 [ 17.341337] devicereleasedriverinternal+0x18c/0x258 [ 17.346551] devicereleasedriver+0x1c/0x30 [ 17.350810] usbdriverreleaseinterface+0x70/0x88 [ 17.355677] procioctl+0x13c/0x228 [ 17.359157] procioctldefault+0x50/0x80 [ 17.363155] usbdevioctl+0x830/0xd08 [ 17.366808] _arm64sysioctl+0x94/0xd0 [ 17.370723] invokesyscall+0x6c/0xf8 [ 17.374377] el0svccommon+0x84/0xe0 [ 17.378030] doel0svc+0x20/0x30 [ 17.381334] el0svc+0x34/0x60 [ 17.384382] el0t64synchandler+0x88/0xf0 [ 17.388554] el0t64_sync+0x180/0x188 [ 17.392208] Code: f9400677 f100a2f4 54fffea0 d503201f (b8350288) [ 17.398289] ---[ end trace 0000000000000000 ]---

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ceac1cb0259de682d78f5c784ef8e0b13022e9d9
Fixed
d8bd79f0eea9c07d90ce870a714ab5c10afaa4b3
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ceac1cb0259de682d78f5c784ef8e0b13022e9d9
Fixed
1219c211ccd061cde002cc5708692efca515a7a0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ceac1cb0259de682d78f5c784ef8e0b13022e9d9
Fixed
61c5a3def90ac729a538e5ca5ff7f461cff72776

Affected versions

v6.*

v6.10
v6.11
v6.11-rc1
v6.11-rc2
v6.11-rc3
v6.11-rc4
v6.11-rc5
v6.11-rc6
v6.11-rc7
v6.11.1
v6.11.10
v6.11.2
v6.11.3
v6.11.4
v6.11.5
v6.11.6
v6.11.7
v6.11.8
v6.11.9
v6.12
v6.12-rc1
v6.12-rc2
v6.12-rc3
v6.12-rc4
v6.12-rc5
v6.12-rc6
v6.12-rc7
v6.12.1

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.11.11
Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.2