
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-36011 is a vulnerability in the Linux kernel's Bluetooth HCI (Host Controller Interface) component, specifically related to a potential null pointer dereference in the hci_le_big_sync_established_evt() function. The vulnerability was discovered and disclosed on May 23, 2024, affecting various versions of the Linux kernel including versions from 6.4.16 up to 6.8.10 (NVD).
The vulnerability is classified as a NULL Pointer Dereference (CWE-476) with a CVSS v3.1 base score of 5.5 (Medium). The issue occurs in the Bluetooth HCI event handling code, specifically in the function hci_le_big_sync_established_evt(), where a potential null pointer dereference could occur when processing BIS (Broadcast Isochronous Stream) connections. The vulnerability was introduced by commit f777d8827817 which added notification functionality for failed BIS connections (Kernel Patch).
The vulnerability could lead to a denial of service condition through a kernel crash when processing certain Bluetooth HCI events. The CVSS scoring indicates that while the vulnerability requires local access and low privileges, it can cause high availability impact to the system (NVD).
The vulnerability requires local access with low privileges and no user interaction to exploit. It specifically affects systems using the Bluetooth functionality of the Linux kernel, particularly when handling BIS connections (NVD).
The vulnerability has been fixed in multiple Linux kernel versions. Ubuntu has released patches for version 24.04 LTS (6.8.0-40.40), and various other distributions have also provided fixes. The fix involves adding a null pointer check before accessing the BIS connection structure (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."