CVE-2024-42132 - CVE House
Back to Database
Status published Unknown CVE-2024-42132

bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caused by handle bigger than HCI_CONN_HANDLE_MAX passed by hci_le_big_sync_established_evt(), which makes code think it's unset connection. Add same check for handle upper bound as in hci_conn_set_handle() to prevent warning.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-42132

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
84cb0143fb8a03bf941c7aaedd56c938c99dafad, 181a42edddf51d5d9697ecdf365d72ebeab5afb0, e9f708beada55426c8d678e2f46af659eb5bf4f0, 6.6.2, 6.5.12, 6.7, 0, 6.6.39, 6.9.9, 6.10

Timeline

Official Publish: July 30th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.