CVE-2024-27416: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.14.328, before 4.15 (fixed in 4.15); from 4.19.297, before 4.19.309 (fixed in 4.19.309); from 5.4.259, before 5.4.271 (fixed in 5.4.271); from 5.10.199, before 5.10.212 (fixed in 5.10.212); from 5.15.137, before 5.15.151 (fixed in 5.15.151); from 6.1.60, before 6.1.81 (fixed in 6.1.81); …

Published 2024-05-17. Last modified 2026-08-04.