CVE-2024-24860: Linux Kernel

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

Affected products

  • Linux Linux Kernel: up to and including 5.5.19; from 6.0, up to and including 6.7.2

Published 2024-02-05. Last modified 2026-06-17.