Home

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix UAF on iso_sock_timeout conn->sk maybe have been unlinked/freed while waiting for iso_conn_lock so this checks if the conn->sk is still valid by checking if it part of iso_sk_list.

PUBLISHED Reserved 2024-10-21 | Published 2024-11-05 | Updated 2025-11-03 | Assigner Linux

Product status

Default status
unaffected

ccf74f2390d60a2f9a75ef496d2564abb478f46a (git) before 876ac72d535fa94f4ac57bba651987c6f990f646
affected

ccf74f2390d60a2f9a75ef496d2564abb478f46a (git) before 14bcb721d241e62fdd18f6f434a2ed2ab6e71a9b
affected

ccf74f2390d60a2f9a75ef496d2564abb478f46a (git) before d75aad1d3143ca68cda52ff80ac392e1bbd84325
affected

ccf74f2390d60a2f9a75ef496d2564abb478f46a (git) before 246b435ad668596aa0e2bbb9d491b6413861211a
affected

Default status
affected

6.0
affected

Any version before 6.0
unaffected

6.1.115 (semver)
unaffected

6.6.59 (semver)
unaffected

6.11.6 (semver)
unaffected

6.12 (original_commit_for_fix)
unaffected

References

lists.debian.org/debian-lts-announce/2025/01/msg00001.html

git.kernel.org/...c/876ac72d535fa94f4ac57bba651987c6f990f646

git.kernel.org/...c/14bcb721d241e62fdd18f6f434a2ed2ab6e71a9b

git.kernel.org/...c/d75aad1d3143ca68cda52ff80ac392e1bbd84325

git.kernel.org/...c/246b435ad668596aa0e2bbb9d491b6413861211a

cve.org (CVE-2024-50124)

nvd.nist.gov (CVE-2024-50124)