CVE-2024-21803 - CVE House
Back to Database
Status published Low CVE-2024-21803

Possible UAF in bt_accept_poll in Linux kernel

Vulnerability Description

Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C. This issue affects Linux kernel: from v2.6.12-rc2 before v6.8-rc1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21803

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • 胡宇轩 <yuxuanhu@buaa.edu.cn>

Affected Vendor

Affected Software

Linux kernel
Vulnerable Versions:
v2.6.12-rc2

Timeline

Official Publish: January 30th, 2024
Last Modified: May 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L

Weaknesses (CWE)