Executive brief
A vulnerability in the Linux kernel's Bluetooth component could allow a local attacker to cause a system crash or potentially access sensitive kernel memory. The issue exists in how the system handles configuration requests for Bluetooth audio (SCO) connections. This could impact the stability of devices using Bluetooth or lead to the exposure of internal system information.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in net/bluetooth/sco.c within the sco_sock_setsockopt() function. The root cause is a failure to validate the 'optlen' parameter before calling copy_from_sockptr(), which can lead to a slab-out-of-bounds access when processing options like BT_VOICE, BT_DEFER_SETUP, or BT_PKT_STATUS. A local attacker with standard user privileges can exploit this by passing a crafted length to the setsockopt system call on a Bluetooth SCO socket. This can result in a kernel panic (DoS) or the leakage of kernel memory contents. Patches have been released across multiple stable kernel branches to introduce length validation via a new bt_copy_from_sockptr() helper.
Affected products
- Linux Linux Kernel 3.8 to 5.10.216, 5.11 to 5.15.178, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7, 6.9-rc1 to 6.9-rc3
Timeline
- 2024-04-05: patched: Initial fix authored by Luiz Augusto von Dentz
- 2024-05-20: advisory: CVE-2024-35967 published
References
- https://git.kernel.org/stable/c/2c2dc87cdebef3fe3b9d7a711a984c70e376e32e
- https://git.kernel.org/stable/c/419a0ffca7010216f0fc265b08558d7394fa0ba7
- https://git.kernel.org/stable/c/51eda36d33e43201e7a4fd35232e069b2c850b01
- https://git.kernel.org/stable/c/72473db90900da970a16ee50ad23c2c38d107d8c
- https://git.kernel.org/stable/c/7bc65d23ba20dcd7ecc094a12c181e594e5eb315
- https://git.kernel.org/stable/c/b0e30c37695b614bee69187f86eaf250e36606ce
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html