CVE-2024-26887: Bluetooth: btusb: Fix memory leak

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: Fix memory leak

This checks if CONFIG_DEV_COREDUMP is enabled before attempting to clone
the skb and also make sure btmtk_process_coredump frees the skb passed
following the same logic.

Classification

CVE ID: CVE-2024-26887

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 5.08% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://git.kernel.org/stable/c/620b9e60e4b55fa55540ce852a0f3c9e6091dbbc
https://git.kernel.org/stable/c/b10e6f6b160a60b98fb7476028f5a95405bbd725
https://git.kernel.org/stable/c/b08bd8f02a24e2b82fece5ac51dc1c3d9aa6c404
https://git.kernel.org/stable/c/79f4127a502c5905f04da1f20a7bbe07103fb77c

Timeline