CVE-2024-35964: Bluetooth: ISO: Fix not validating setsockopt user input

0.0 CVSS

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: Fix not validating setsockopt user input

Check user input length before copying data.

Classification

CVE ID: CVE-2024-35964

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://git.kernel.org/stable/c/cec736e60dc18d91b88af28d96664bff284b02d1
https://git.kernel.org/stable/c/6a6baa1ee7a9df33adbf932305053520b9741b35
https://git.kernel.org/stable/c/0c4a89f4690478969729c7ba5f69d53d8516aa12
https://git.kernel.org/stable/c/9e8742cdfc4b0e65266bb4a901a19462bda9285e

Timeline