CVE-2024-53144: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always request user confirmation with confirm_hint set since the likes of bluetoothd have dedicated policy around JUST_WORKS method (e.g. main.conf:JustWorksRepairing). CVE: CVE-2024-8805

Affected products

  • Linux Linux Kernel: from 3.2.61, before 3.3 (fixed in 3.3); from 3.4.98, before 3.5 (fixed in 3.5); from 3.10.48, before 3.11 (fixed in 3.11); from 3.12.25, before 3.13 (fixed in 3.13); from 3.14.12, before 3.15 (fixed in 3.15); from 3.15.5, before 3.16 (fixed in 3.16); …

Published 2024-12-17. Last modified 2026-08-04.