Bluetooth: hci_core: Fix possible buffer overflow

Summary

CVECVE-2024-26889
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-04-17 11:15:10 UTC
Updated2026-05-12 12:16:24 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix possible buffer overflow struct hci_dev_info has a fixed size name[8] field so in the event that hdev->name is bigger than that strcpy would attempt to write past its size, so this fixes this problem by switching to use strscpy.

Risk And Classification

Primary CVSS: v3.1 5.5 MEDIUM from ADP

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem Types: CWE-120 | CWE-120 CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')


VersionSourceTypeScoreSeverityVector
3.1ADPDECLARED5.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
3.1134c704f-9b21-4f2e-91b3-4a467353bcc0Secondary5.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 194ab82c1ea187512ff2f822124bd05b63fc9f76 6d5a9d4a7bcbb7534ce45a18a52e7bd23e69d8ac git Not specified
CNA Linux Linux affected b48595f5b1c6e81e06e164e7d2b7a30b1776161e 54a03e4ac1a41edf8a5087bd59f8241b0de96d3d git Not specified
CNA Linux Linux affected ffb060b136dd75a033ced0fc0aed2882c02e8b56 d47e6c1932cee02954ea588c9f09fd5ecefeadfc git Not specified
CNA Linux Linux affected bbec1724519ecd9c468d1186a8f30b7567175bfb 2e845867b4e279eff0a19ade253390470e07e8a1 git Not specified
CNA Linux Linux affected dcda165706b9fbfd685898d46a6749d7d397e0c0 a41c8efe659caed0e21422876bbb6b73c15b5244 git Not specified
CNA Linux Linux affected dcda165706b9fbfd685898d46a6749d7d397e0c0 8c28598a2c29201d2ba7fc37539a7d41c264fb10 git Not specified
CNA Linux Linux affected dcda165706b9fbfd685898d46a6749d7d397e0c0 2edce8e9a99dd5e4404259d52e754fdc97fb42c2 git Not specified
CNA Linux Linux affected dcda165706b9fbfd685898d46a6749d7d397e0c0 81137162bfaa7278785b24c1fd2e9e74f082e8e4 git Not specified
CNA Linux Linux affected d9ce7d438366431e5688be98d8680336ce0a0f8d git Not specified
CNA Linux Linux affected a55d53ad5c86aee3f6da50ee73626008997673fa git Not specified
CNA Linux Linux affected 5558f4312dca43cebfb9a1aab3d632be91bbb736 git Not specified
CNA Linux Linux affected 6.6 Not specified
CNA Linux Linux unaffected 6.6 semver Not specified
CNA Linux Linux unaffected 4.19.311 4.19.* semver Not specified
CNA Linux Linux unaffected 5.4.273 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.214 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.153 5.15.* semver Not specified
CNA Linux Linux unaffected 6.6.23 6.6.* semver Not specified
CNA Linux Linux unaffected 6.7.11 6.7.* semver Not specified
CNA Linux Linux unaffected 6.8.2 6.8.* semver Not specified
CNA Linux Linux unaffected 6.9 * original_commit_for_fix Not specified
ADP Siemens SIMATIC S7-1500 TM MFP - GNU/Linux Subsystem affected * custom Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/68644bf5ec6baaff40fc39b3529c874bfda709bd af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/8c28598a2c29201d2ba7fc37539a7d41c264fb10 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/a41c8efe659caed0e21422876bbb6b73c15b5244 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2024/06/msg00017.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Mailing List, Third Party Advisory
git.kernel.org/stable/c/54a03e4ac1a41edf8a5087bd59f8241b0de96d3d af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/d47e6c1932cee02954ea588c9f09fd5ecefeadfc af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/2e845867b4e279eff0a19ade253390470e07e8a1 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
cert-portal.siemens.com/productcert/html/ssa-265688.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
git.kernel.org/stable/c/2edce8e9a99dd5e4404259d52e754fdc97fb42c2 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/81137162bfaa7278785b24c1fd2e9e74f082e8e4 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/6d5a9d4a7bcbb7534ce45a18a52e7bd23e69d8ac af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2024/06/msg00020.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Mailing List, Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report