CVE-2024-36880 (GCVE-0-2024-36880)
Vulnerability from cvelistv5
Published
2024-05-30 15:28
Modified
2026-08-05 11:31
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: add missing firmware sanity checks Add the missing sanity checks when parsing the firmware files before downloading them to avoid accessing and corrupting memory beyond the vmalloced buffer.
Impacted products
Vendor Product Version
Linux Linux Version: 83e81961ff7ef75f97756f316caea5aa6bcc19cc
Version: 83e81961ff7ef75f97756f316caea5aa6bcc19cc
Version: 83e81961ff7ef75f97756f316caea5aa6bcc19cc
Version: 83e81961ff7ef75f97756f316caea5aa6bcc19cc
Version: 83e81961ff7ef75f97756f316caea5aa6bcc19cc
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-36880",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-03T16:40:42.596232Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:47:41.364Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T03:43:49.156Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ed53949cc92e28aaa3463d246942bda1fbb7f307"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/1caceadfb50432dbf6d808796cb6c34ebb6d662c"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/427281f9498ed614f9aabc80e46ec077c487da6d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/02f05ed44b71152d5e11d29be28aed91c0489b4e"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/2e4edfa1e2bd821a317e7d006517dcf2f3fac68d"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/bluetooth/btqca.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ed53949cc92e28aaa3463d246942bda1fbb7f307",
              "status": "affected",
              "version": "83e81961ff7ef75f97756f316caea5aa6bcc19cc",
              "versionType": "git"
            },
            {
              "lessThan": "1caceadfb50432dbf6d808796cb6c34ebb6d662c",
              "status": "affected",
              "version": "83e81961ff7ef75f97756f316caea5aa6bcc19cc",
              "versionType": "git"
            },
            {
              "lessThan": "427281f9498ed614f9aabc80e46ec077c487da6d",
              "status": "affected",
              "version": "83e81961ff7ef75f97756f316caea5aa6bcc19cc",
              "versionType": "git"
            },
            {
              "lessThan": "02f05ed44b71152d5e11d29be28aed91c0489b4e",
              "status": "affected",
              "version": "83e81961ff7ef75f97756f316caea5aa6bcc19cc",
              "versionType": "git"
            },
            {
              "lessThan": "2e4edfa1e2bd821a317e7d006517dcf2f3fac68d",
              "status": "affected",
              "version": "83e81961ff7ef75f97756f316caea5aa6bcc19cc",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/bluetooth/btqca.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.3"
            },
            {
              "lessThan": "4.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.159",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.91",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.31",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.159",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.91",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.31",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.10",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: add missing firmware sanity checks\n\nAdd the missing sanity checks when parsing the firmware files before\ndownloading them to avoid accessing and corrupting memory beyond the\nvmalloced buffer."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The malformed data is a firmware/NVM file read via request_firmware() from a local firmware search path (/lib/firmware*, firmware_class.path); the Bluetooth controller can only steer filename selection, not content, so there is no remote or adjacent input into the parser. Exploitation therefore requires local access to place the crafted file.\nAC:L - A crafted NVM file with a 24-bit length field of 0xffffff deterministically drives the unbounded while-loop past the end of the exactly-sized vmalloc buffer on every Bluetooth setup; there is no race, timing window, or memory-layout luck required to trigger the out-of-bounds walk.\nPR:L - The attacker needs write access to a firmware search path rather than kernel privileges \u2014 on embedded, automotive, Android and IoT deployments this is routinely held by a non-root firmware/OTA service account or a writable vendor partition, so a low-privileged local principal can convert file-write into kernel memory corruption.\nUI:N - qca_tlv_check_data() runs from hdev-\u003esetup during HCI device bring-up, which happens automatically at boot, on bluetoothd start, on rfkill unblock, and on QCA subsystem-restart recovery; no deliberate action by another user is needed.\nS:U - The out-of-bounds reads and writes stay within the kernel\u0027s own memory and security authority, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The TLV_TYPE_NVM loop performs an essentially unbounded out-of-bounds read walking up to 16 MiB past a page-sized vmalloc allocation, and the resulting memory corruption of adjacent vmalloc objects can be leveraged for disclosure, so this is not a small bounded read.\nI:H - The parser writes out of bounds (tlv_nvm-\u003edata[0] |= 0x80, data[1]/data[2] = nvm_baud_rate, data[0] |= 0x01) at offsets driven by a tag_len that is itself read from OOB memory, letting the walk skip vmalloc guard pages and corrupt neighbouring allocations such as module data or VMAP_STACK kernel stacks \u2014 a control-flow-relevant write primitive.\nA:H - Walking a multi-megabyte range past a small vmalloc buffer will hit a vmalloc guard page or unmapped region, producing an oops/panic during Bluetooth initialisation and leaving the device unusable."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:31:47.937Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ed53949cc92e28aaa3463d246942bda1fbb7f307"
        },
        {
          "url": "https://git.kernel.org/stable/c/1caceadfb50432dbf6d808796cb6c34ebb6d662c"
        },
        {
          "url": "https://git.kernel.org/stable/c/427281f9498ed614f9aabc80e46ec077c487da6d"
        },
        {
          "url": "https://git.kernel.org/stable/c/02f05ed44b71152d5e11d29be28aed91c0489b4e"
        },
        {
          "url": "https://git.kernel.org/stable/c/2e4edfa1e2bd821a317e7d006517dcf2f3fac68d"
        }
      ],
      "title": "Bluetooth: qca: add missing firmware sanity checks",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-36880",
    "datePublished": "2024-05-30T15:28:51.518Z",
    "dateReserved": "2024-05-30T15:25:07.064Z",
    "dateUpdated": "2026-08-05T11:31:47.937Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/ed53949cc92e28aaa3463d246942bda1fbb7f307\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/1caceadfb50432dbf6d808796cb6c34ebb6d662c\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/427281f9498ed614f9aabc80e46ec077c487da6d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/02f05ed44b71152d5e11d29be28aed91c0489b4e\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/2e4edfa1e2bd821a317e7d006517dcf2f3fac68d\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T03:43:49.156Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-36880\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-03T16:40:42.596232Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-03T16:41:45.672Z\"}}], \"cna\": {\"title\": \"Bluetooth: qca: add missing firmware sanity checks\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The malformed data is a firmware/NVM file read via request_firmware() from a local firmware search path (/lib/firmware*, firmware_class.path); the Bluetooth controller can only steer filename selection, not content, so there is no remote or adjacent input into the parser. Exploitation therefore requires local access to place the crafted file.\\nAC:L - A crafted NVM file with a 24-bit length field of 0xffffff deterministically drives the unbounded while-loop past the end of the exactly-sized vmalloc buffer on every Bluetooth setup; there is no race, timing window, or memory-layout luck required to trigger the out-of-bounds walk.\\nPR:L - The attacker needs write access to a firmware search path rather than kernel privileges \\u2014 on embedded, automotive, Android and IoT deployments this is routinely held by a non-root firmware/OTA service account or a writable vendor partition, so a low-privileged local principal can convert file-write into kernel memory corruption.\\nUI:N - qca_tlv_check_data() runs from hdev-\u003esetup during HCI device bring-up, which happens automatically at boot, on bluetoothd start, on rfkill unblock, and on QCA subsystem-restart recovery; no deliberate action by another user is needed.\\nS:U - The out-of-bounds reads and writes stay within the kernel\u0027s own memory and security authority, with no crossing of a VM, IOMMU, or sandbox boundary.\\nC:H - The TLV_TYPE_NVM loop performs an essentially unbounded out-of-bounds read walking up to 16 MiB past a page-sized vmalloc allocation, and the resulting memory corruption of adjacent vmalloc objects can be leveraged for disclosure, so this is not a small bounded read.\\nI:H - The parser writes out of bounds (tlv_nvm-\u003edata[0] |= 0x80, data[1]/data[2] = nvm_baud_rate, data[0] |= 0x01) at offsets driven by a tag_len that is itself read from OOB memory, letting the walk skip vmalloc guard pages and corrupt neighbouring allocations such as module data or VMAP_STACK kernel stacks \\u2014 a control-flow-relevant write primitive.\\nA:H - Walking a multi-megabyte range past a small vmalloc buffer will hit a vmalloc guard page or unmapped region, producing an oops/panic during Bluetooth initialisation and leaving the device unusable.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"83e81961ff7ef75f97756f316caea5aa6bcc19cc\", \"lessThan\": \"ed53949cc92e28aaa3463d246942bda1fbb7f307\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"83e81961ff7ef75f97756f316caea5aa6bcc19cc\", \"lessThan\": \"1caceadfb50432dbf6d808796cb6c34ebb6d662c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"83e81961ff7ef75f97756f316caea5aa6bcc19cc\", \"lessThan\": \"427281f9498ed614f9aabc80e46ec077c487da6d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"83e81961ff7ef75f97756f316caea5aa6bcc19cc\", \"lessThan\": \"02f05ed44b71152d5e11d29be28aed91c0489b4e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"83e81961ff7ef75f97756f316caea5aa6bcc19cc\", \"lessThan\": \"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/bluetooth/btqca.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.3\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.3\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.159\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.91\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.31\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.10\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/bluetooth/btqca.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/ed53949cc92e28aaa3463d246942bda1fbb7f307\"}, {\"url\": \"https://git.kernel.org/stable/c/1caceadfb50432dbf6d808796cb6c34ebb6d662c\"}, {\"url\": \"https://git.kernel.org/stable/c/427281f9498ed614f9aabc80e46ec077c487da6d\"}, {\"url\": \"https://git.kernel.org/stable/c/02f05ed44b71152d5e11d29be28aed91c0489b4e\"}, {\"url\": \"https://git.kernel.org/stable/c/2e4edfa1e2bd821a317e7d006517dcf2f3fac68d\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nBluetooth: qca: add missing firmware sanity checks\\n\\nAdd the missing sanity checks when parsing the firmware files before\\ndownloading them to avoid accessing and corrupting memory beyond the\\nvmalloced buffer.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.159\", \"versionStartIncluding\": \"4.3\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.91\", \"versionStartIncluding\": \"4.3\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.31\", \"versionStartIncluding\": \"4.3\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.10\", \"versionStartIncluding\": \"4.3\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"4.3\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:31:47.937Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-36880\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:31:47.937Z\", \"dateReserved\": \"2024-05-30T15:25:07.064Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-30T15:28:51.518Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…