Use of obsolete function i nLinux kernel Bluetooth



| Updated: 2025-05-13
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2024-38620
CWE-ID CWE-477
Exploitation vector Local
Public exploit N/A
Vulnerable software
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Use of obsolete function

EUVDB-ID: #VU94119

Risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-38620

CWE-ID: CWE-477 - Use of Obsolete Function

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to kernel contains obsolete support for HCI_AMP. A local user can abuse such support, which can lead to potential security issues.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Linux kernel: 6.6 - 6.8.11

CPE2.3 External links

https://git.kernel.org/stable/c/5af2e235b0d5b797e9531a00c50058319130e156
https://git.kernel.org/stable/c/d3c7b012d912b31ad23b9349c0e499d6dddd48ec
https://git.kernel.org/stable/c/af1d425b6dc67cd67809f835dd7afb6be4d43e03
https://git.kernel.org/stable/c/84a4bb6548a29326564f0e659fb8064503ecc1c7
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.10
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.33
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8.12


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###