CVE-2024-26889: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix possible buffer overflow struct hci_dev_info has a fixed size name[8] field so in the event that hdev->name is bigger than that strcpy would attempt to write past its size, so this fixes this problem by switching to use strscpy.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.14.328, before 4.15 (fixed in 4.15); from 4.19.297, before 4.19.311 (fixed in 4.19.311); from 5.4.259, before 5.4.273 (fixed in 5.4.273); from 5.10.199, before 5.10.214 (fixed in 5.10.214); from 5.15.137, before 5.15.153 (fixed in 5.15.153); from 6.1.60, before 6.1.83 (fixed in 6.1.83); …

Published 2024-04-17. Last modified 2026-06-17.