CVE-2024-42133: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Ignore too large handle values in BIG hci_le_big_sync_established_evt is necessary to filter out cases where the handle value is belonging to ida id range, otherwise ida will be erroneously released in hci_conn_cleanup.
Affected products
- Linux Linux Kernel: from 6.5.12, before 6.6 (fixed in 6.6); from 6.6.2, before 6.6.39 (fixed in 6.6.39); from 6.7, before 6.9.9 (fixed in 6.9.9); version 6.10 only
Published 2024-07-30. Last modified 2026-08-04.