CVE-2024-24857: Debian Linux

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: up to and including 3.19.8; from 6.0, up to and including 6.6.25; from 6.7, before 6.7.12 (fixed in 6.7.12); version 6.8 only

Published 2024-02-05. Last modified 2026-06-17.