Fix Firmware Check Error Path to Prevent Memory Leak
CVE-2024-36942

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
30 May 2024

What is CVE-2024-36942?

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: qca: fix firmware check error path

A recent commit fixed the code that parses the firmware files before downloading them to the controller but introduced a memory leak in case the sanity checks ever fail.

Make sure to free the firmware buffer before returning on errors.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 580bcd6bf24f9975f97d81d5ef1b64cca9240df9

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 064688d70c33bb5b49dde6e972b9379a8b045d8a

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7bcba557d5c37cd09ecd5abbe7d50deb86c36d3f

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.