| { |
| "containers": { |
| "cna": { |
| "providerMetadata": { |
| "orgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038" |
| }, |
| "descriptions": [ |
| { |
| "lang": "en", |
| "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix possible buffer overflow\n\nstruct hci_dev_info has a fixed size name[8] field so in the event that\nhdev->name is bigger than that strcpy would attempt to write past its\nsize, so this fixes this problem by switching to use strscpy." |
| } |
| ], |
| "affected": [ |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "unaffected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "net/bluetooth/hci_core.c" |
| ], |
| "versions": [ |
| { |
| "version": "194ab82c1ea187512ff2f822124bd05b63fc9f76", |
| "lessThan": "6d5a9d4a7bcbb7534ce45a18a52e7bd23e69d8ac", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "b48595f5b1c6e81e06e164e7d2b7a30b1776161e", |
| "lessThan": "54a03e4ac1a41edf8a5087bd59f8241b0de96d3d", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "ffb060b136dd75a033ced0fc0aed2882c02e8b56", |
| "lessThan": "d47e6c1932cee02954ea588c9f09fd5ecefeadfc", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "bbec1724519ecd9c468d1186a8f30b7567175bfb", |
| "lessThan": "2e845867b4e279eff0a19ade253390470e07e8a1", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "dcda165706b9fbfd685898d46a6749d7d397e0c0", |
| "lessThan": "a41c8efe659caed0e21422876bbb6b73c15b5244", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "dcda165706b9fbfd685898d46a6749d7d397e0c0", |
| "lessThan": "8c28598a2c29201d2ba7fc37539a7d41c264fb10", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "dcda165706b9fbfd685898d46a6749d7d397e0c0", |
| "lessThan": "2edce8e9a99dd5e4404259d52e754fdc97fb42c2", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "dcda165706b9fbfd685898d46a6749d7d397e0c0", |
| "lessThan": "81137162bfaa7278785b24c1fd2e9e74f082e8e4", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "d9ce7d438366431e5688be98d8680336ce0a0f8d", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "a55d53ad5c86aee3f6da50ee73626008997673fa", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "5558f4312dca43cebfb9a1aab3d632be91bbb736", |
| "status": "affected", |
| "versionType": "git" |
| } |
| ] |
| }, |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "affected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "net/bluetooth/hci_core.c" |
| ], |
| "versions": [ |
| { |
| "version": "6.6", |
| "status": "affected" |
| }, |
| { |
| "version": "0", |
| "lessThan": "6.6", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "4.19.311", |
| "lessThanOrEqual": "4.19.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.4.273", |
| "lessThanOrEqual": "5.4.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.10.214", |
| "lessThanOrEqual": "5.10.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.15.153", |
| "lessThanOrEqual": "5.15.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.6.23", |
| "lessThanOrEqual": "6.6.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.7.11", |
| "lessThanOrEqual": "6.7.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.8.2", |
| "lessThanOrEqual": "6.8.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.9", |
| "lessThanOrEqual": "*", |
| "status": "unaffected", |
| "versionType": "original_commit_for_fix" |
| } |
| ] |
| } |
| ], |
| "cpeApplicability": [ |
| { |
| "nodes": [ |
| { |
| "operator": "OR", |
| "negate": false, |
| "cpeMatch": [ |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19.297", |
| "versionEndExcluding": "4.19.311" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "5.4.259", |
| "versionEndExcluding": "5.4.273" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "5.10.199", |
| "versionEndExcluding": "5.10.214" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "5.15.137", |
| "versionEndExcluding": "5.15.153" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.6", |
| "versionEndExcluding": "6.6.23" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.6", |
| "versionEndExcluding": "6.7.11" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.6", |
| "versionEndExcluding": "6.8.2" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.6", |
| "versionEndExcluding": "6.9" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.14.328" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.1.60" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.5.9" |
| } |
| ] |
| } |
| ] |
| } |
| ], |
| "references": [ |
| { |
| "url": "https://git.kernel.org/stable/c/6d5a9d4a7bcbb7534ce45a18a52e7bd23e69d8ac" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/54a03e4ac1a41edf8a5087bd59f8241b0de96d3d" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/d47e6c1932cee02954ea588c9f09fd5ecefeadfc" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/2e845867b4e279eff0a19ade253390470e07e8a1" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/a41c8efe659caed0e21422876bbb6b73c15b5244" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/8c28598a2c29201d2ba7fc37539a7d41c264fb10" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/2edce8e9a99dd5e4404259d52e754fdc97fb42c2" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/81137162bfaa7278785b24c1fd2e9e74f082e8e4" |
| } |
| ], |
| "title": "Bluetooth: hci_core: Fix possible buffer overflow", |
| "x_generator": { |
| "engine": "bippy-1.2.0" |
| } |
| } |
| }, |
| "cveMetadata": { |
| "assignerOrgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038", |
| "cveID": "CVE-2024-26889", |
| "requesterUserId": "gregkh@kernel.org", |
| "serial": "1", |
| "state": "PUBLISHED" |
| }, |
| "dataType": "CVE_RECORD", |
| "dataVersion": "5.0" |
| } |