CVE-2024-56605

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-56605
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-56605.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-56605
Downstream
Related
Published
2024-12-27T14:51:10.344Z
Modified
2025-11-28T02:35:49.357957Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2capsockcreate()

btsockalloc() allocates the sk object and attaches it to the provided sock object. On error l2capsockalloc() frees the sk object, but the dangling pointer is still attached to the sock object, which may create use-after-free in other code.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56605.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
f6ad641646b67f29c7578dcd6c25813c7dcbf51e
Fixed
daa13175a6dea312a76099066cb4cbd4fc959a84
Fixed
a8677028dd5123e5e525b8195483994d87123de4
Fixed
bb2f2342a6ddf7c04f9aefbbfe86104cd138e629
Fixed
8ad09ddc63ace3950ac43db6fbfe25b40f589dd6
Fixed
61686abc2f3c2c67822aa23ce6f160467ec83d35
Fixed
7c4f78cdb8e7501e9f92d291a7d956591bf73be9

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.287
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.231
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.174
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.120
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.66
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.5