Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-50078— Bluetooth: Call iso_exit() on module unload

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在模块卸载时未调用iso_exit函数,导致注册的struct proto变为无效。

CVSS 7.8 · High EPSS 0.21% · P12

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux ccf74f2390d60a2f9a75ef496d2564abb478f46a< 4af7ba39a1a02e16ee8cd0d3b6c6657f51b8ad7a affected
ccf74f2390d60a2f9a75ef496d2564abb478f46a< 05f84d86169b2ebac185c5736a256823d42c425b affected
ccf74f2390d60a2f9a75ef496d2564abb478f46a< f905a7d95091e0d2605a3a1a157a9351f09ab2e1 affected
ccf74f2390d60a2f9a75ef496d2564abb478f46a< d458cd1221e9e56da3b2cc5518ad3225caa91f20 affected
6.0 affected
< 6.0 unaffected
6.1.114≤ 6.1.* unaffected
6.6.58≤ 6.6.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-50078

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bluetooth: Call iso_exit() on module unload
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Call iso_exit() on module unload If iso_init() has been called, iso_exit() must be called on module unload. Without that, the struct proto that iso_init() registered with proto_register() becomes invalid, which could cause unpredictable problems later. In my case, with CONFIG_LIST_HARDENED and CONFIG_BUG_ON_DATA_CORRUPTION enabled, loading the module again usually triggers this BUG(): list_add corruption. next->prev should be prev (ffffffffb5355fd0), but was 0000000000000068. (next=ffffffffc0a010d0). ------------[ cut here ]------------ kernel BUG at lib/list_debug.c:29! Oops: invalid opcode: 0000 [#1] PREEMPT SMP PTI CPU: 1 PID: 4159 Comm: modprobe Not tainted 6.10.11-4+bt2-ao-desktop #1 RIP: 0010:__list_add_valid_or_report+0x61/0xa0 ... __list_add_valid_or_report+0x61/0xa0 proto_register+0x299/0x320 hci_sock_init+0x16/0xc0 [bluetooth] bt_init+0x68/0xd0 [bluetooth] __pfx_bt_init+0x10/0x10 [bluetooth] do_one_initcall+0x80/0x2f0 do_init_module+0x8b/0x230 __do_sys_init_module+0x15f/0x190 do_syscall_64+0x68/0x110 ...
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在模块卸载时未调用iso_exit函数,导致注册的struct proto变为无效。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ccf74f2390d60a2f9a75ef496d2564abb478f46a ~ 4af7ba39a1a02e16ee8cd0d3b6c6657f51b8ad7a -
Linux Linux 6.0 -

II. Public POCs for CVE-2024-50078

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-50078

登录查看更多情报信息。

Patches & Fixes for CVE-2024-50078 (1)

Same Patch Batch · Linux · 2024-10-29 · 21 CVEs total

CVE-2024-50086 9.8 CRITICAL ksmbd: fix user-after-free from session log off
CVE-2024-50085 9.8 CRITICAL mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
CVE-2024-50075 8.0 HIGH xhci: tegra: fix checked USB2 port number
CVE-2024-50087 7.8 HIGH btrfs: fix uninitialized pointer free on read_alloc_one_name() error
CVE-2024-50073 7.8 HIGH tty: n_gsm: Fix use-after-free in gsm_cleanup_mux
CVE-2024-50074 7.8 HIGH parport: Proper fix for array out-of-bounds access
CVE-2024-50077 7.8 HIGH Bluetooth: ISO: Fix multiple init when debugfs is disabled
CVE-2024-50082 7.8 HIGH blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race
CVE-2024-50088 7.8 HIGH btrfs: fix uninitialized pointer free in add_inode_ref()
CVE-2024-50081 blk-mq: setup queue ->tag_set before initializing hctx
CVE-2024-50080 ublk: don't allow user copy for unprivileged device
CVE-2024-50079 io_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work
CVE-2024-50076 vt: prevent kernel-infoleak in con_font_get()
CVE-2024-50083 tcp: fix mptcp DSS corruption due to large pmtu xmit
CVE-2024-50084 net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()
CVE-2024-50072 x86/bugs: Use code segment selector for VERW operand
CVE-2024-50071 pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func()
CVE-2024-50070 pinctrl: stm32: check devm_kasprintf() returned value
CVE-2024-50069 pinctrl: apple: check devm_kasprintf() returned value
CVE-2024-50068 mm/damon/tests/sysfs-kunit.h: fix memory leak in damon_sysfs_test_add_targets()

IV. Related Vulnerabilities

V. Comments for CVE-2024-50078

No comments yet


Leave a comment