CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-57987: Bluetooth: btrtl: check for NULL in btrtl_setup_realtek()

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btrtl: check for NULL in btrtl_setup_realtek()

If insert an USB dongle which chip is not maintained in ic_id_table, it
will hit the NULL point accessed. Add a null point check to avoid the
Kernel Oops.

Classification

CVE ID: CVE-2024-57987

Affected Products

Vendor: Linux, Linux

Product: Linux, Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 1.68% (scored less or equal to compared to others)

EPSS Date: 2025-03-27 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-57987
https://git.kernel.org/stable/c/1158ad8e8abb361d4b2aaa010c9af74de20ab82b
https://git.kernel.org/stable/c/02f9da874e5e4626f81772eacc18967921998a71
https://git.kernel.org/stable/c/3c15082f3567032d196e8760753373332508c2ca

Timeline