CVE-2024-36033
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-36033 is a vulnerability in the Linux kernel's Bluetooth QCA driver that was discovered and disclosed in May 2024. The vulnerability specifically affects the board ID fetching functionality in the Bluetooth QCA driver, which could potentially leak slab data when requesting firmware (Kernel Git).

Technical details

The vulnerability stems from a missing sanity check when fetching the board ID in the Linux kernel's Bluetooth QCA driver. The issue occurs in the qca_read_fw_board_id function where there was no validation of the data length before accessing it, potentially leading to slab data leakage during firmware requests. The fix involves adding a length check to ensure the received data buffer contains at least 3 bytes before accessing the board ID information (Kernel Git).

Impact

The vulnerability could lead to information disclosure through slab data leakage when requesting firmware for QCA Bluetooth devices. This could potentially expose sensitive kernel memory contents to unauthorized users (Kernel Git).

Mitigation and workarounds

The vulnerability has been patched in the Linux kernel with a fix that adds proper sanity checks when fetching the board ID. The patch has been backported to multiple stable kernel versions. Users should update their Linux kernel to a version that includes this security fix (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68480NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-uek64k-devel
NoYesAug 06, 2026
CVE-2026-64582NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-aws-fips
NoYesAug 05, 2026
CVE-2026-64579NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 05, 2026
CVE-2026-64576NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-modules
NoYesAug 05, 2026
CVE-2026-64575NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.17
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management