Junglewise Threat Intelligence

CVE-2024-35978: Linux Kernel memory leak in Bluetooth hci_req_sync_complete

CVE-2024-35978 · Severity: medium · CVSS 5.5 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Bluetooth subsystem could allow a local user to cause a memory leak. Over time, this could exhaust system memory, leading to a denial-of-service condition where the system becomes unstable or crashes. This affects various versions of the Linux kernel used in servers, workstations, and embedded devices.

Technical details

A memory leak vulnerability (CWE-401) exists in the Linux kernel Bluetooth subsystem within the 'hci_req_sync_complete()' function in 'net/bluetooth/hci_request.c'. The root cause is the failure to free the previous synchronous request state (specifically the socket buffer 'req_skb') before assigning a reference to a new one. A local attacker with low privileges can exploit this to gradually exhaust system memory. The issue has been resolved in multiple stable kernel branches by ensuring 'kfree_skb' is called on the existing request state before a new reference is acquired via 'skb_get'.

Affected products

  • Linux Linux Kernel 4.1 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.156, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7

Timeline

  • 2024-04-02: other: Patch authored
  • 2024-05-20: disclosed: CVE published

References

Related threats