CVE-2024-53144 (GCVE-0-2024-53144)
Vulnerability from cvelistv5
Published
2024-12-17 15:55
Modified
2026-08-05 11:44
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always request user confirmation with confirm_hint set since the likes of bluetoothd have dedicated policy around JUST_WORKS method (e.g. main.conf:JustWorksRepairing). CVE: CVE-2024-8805
Impacted products
Vendor Product Version
Linux Linux Version: ba15a58b179ed76a7e887177f2b06de12c58ec8f
Version: ba15a58b179ed76a7e887177f2b06de12c58ec8f
Version: ba15a58b179ed76a7e887177f2b06de12c58ec8f
Version: ba15a58b179ed76a7e887177f2b06de12c58ec8f
Version: ba15a58b179ed76a7e887177f2b06de12c58ec8f
Version: ba15a58b179ed76a7e887177f2b06de12c58ec8f
Version: ba15a58b179ed76a7e887177f2b06de12c58ec8f
Version: 373d1dfcffc63c68184419264a7eaed422c7958e
Version: bc96ff59b2f19e924d9e15e24cee19723d674b92
Version: 6ab84785311dc4d0348e6bd4e1c491293b770b98
Version: 778763287ded64dd5c022435d3e0e3182f148a64
Version: 9a5fcacabde0fe11456f4a1e88072c01846cea25
Version: 039da39a616103ec7ab8ac351bfb317854e5507c
Version: 3.2.61   
Version: 3.4.98   
Version: 3.10.48   
Version: 3.12.25   
Version: 3.14.12   
Version: 3.15.5   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:29:43.667Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/hci_event.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "baaa50c6f91ea5a9c7503af51f2bc50e6568b66b",
              "status": "affected",
              "version": "ba15a58b179ed76a7e887177f2b06de12c58ec8f",
              "versionType": "git"
            },
            {
              "lessThan": "22b49d6e4f399a390c70f3034f5fbacbb9413858",
              "status": "affected",
              "version": "ba15a58b179ed76a7e887177f2b06de12c58ec8f",
              "versionType": "git"
            },
            {
              "lessThan": "d17c631ba04e960eb6f8728b10d585de20ac4f71",
              "status": "affected",
              "version": "ba15a58b179ed76a7e887177f2b06de12c58ec8f",
              "versionType": "git"
            },
            {
              "lessThan": "830c03e58beb70b99349760f822e505ecb4eeb7e",
              "status": "affected",
              "version": "ba15a58b179ed76a7e887177f2b06de12c58ec8f",
              "versionType": "git"
            },
            {
              "lessThan": "ad7adfb95f64a761e4784381e47bee1a362eb30d",
              "status": "affected",
              "version": "ba15a58b179ed76a7e887177f2b06de12c58ec8f",
              "versionType": "git"
            },
            {
              "lessThan": "5291ff856d2c5177b4fe9c18828312be30213193",
              "status": "affected",
              "version": "ba15a58b179ed76a7e887177f2b06de12c58ec8f",
              "versionType": "git"
            },
            {
              "lessThan": "b25e11f978b63cb7857890edb3a698599cddb10e",
              "status": "affected",
              "version": "ba15a58b179ed76a7e887177f2b06de12c58ec8f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "373d1dfcffc63c68184419264a7eaed422c7958e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bc96ff59b2f19e924d9e15e24cee19723d674b92",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6ab84785311dc4d0348e6bd4e1c491293b770b98",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "778763287ded64dd5c022435d3e0e3182f148a64",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9a5fcacabde0fe11456f4a1e88072c01846cea25",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "039da39a616103ec7ab8ac351bfb317854e5507c",
              "versionType": "git"
            },
            {
              "lessThan": "3.3",
              "status": "affected",
              "version": "3.2.61",
              "versionType": "semver"
            },
            {
              "lessThan": "3.5",
              "status": "affected",
              "version": "3.4.98",
              "versionType": "semver"
            },
            {
              "lessThan": "3.11",
              "status": "affected",
              "version": "3.10.48",
              "versionType": "semver"
            },
            {
              "lessThan": "3.13",
              "status": "affected",
              "version": "3.12.25",
              "versionType": "semver"
            },
            {
              "lessThan": "3.15",
              "status": "affected",
              "version": "3.14.12",
              "versionType": "semver"
            },
            {
              "lessThan": "3.16",
              "status": "affected",
              "version": "3.15.5",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/bluetooth/hci_event.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.16"
            },
            {
              "lessThan": "3.16",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.236",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.180",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.55",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.236",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.180",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.55",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.14",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.3",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.2.61",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.4.98",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.10.48",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.12.25",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.14.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.15.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE\n\nThis aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4\n(\"Bluetooth: Always request for user confirmation for Just Works\")\nalways request user confirmation with confirm_hint set since the\nlikes of bluetoothd have dedicated policy around JUST_WORKS method\n(e.g. main.conf:JustWorksRepairing).\n\nCVE: CVE-2024-8805"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - The vulnerable code path is driven entirely by BR/EDR HCI events generated from an attacker-controlled Bluetooth peer (Connection Request, IO Capability Response, User Confirmation Request), requiring only radio proximity to the target. Per kernel scoring guidance Bluetooth reachability is Adjacent.\nAC:L - The attacker fully controls both parameters that select the vulnerable branch \u2014 its own IO capability (NoInputNoOutput) and authentication requirements (bonding without MITM) \u2014 making the silent auto-accept deterministic with no race, no memory-layout dependency, and no non-default kernel or BlueZ configuration.\nPR:N - The attacker is an entirely unknown, unpaired, unauthenticated remote device with no prior link key; the bug is reached during the initial pairing handshake before any trust relationship exists.\nUI:N - The defect is precisely that the kernel never invokes mgmt_user_confirm_request, so bluetoothd and the user are never consulted and the bond completes silently with no prompt, notification, or action from the victim.\nS:U - The vulnerable component and the compromised resources are the same host under a single security authority; no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The unauthorized persistent bond makes the attacker a trusted device, enabling connections to profiles that expose highly sensitive data (PBAP phonebook and call logs, MAP SMS, OBEX FTP, audio) on phones and automotive head units, and HID keystroke injection escalates this to arbitrary user-level file read.\nI:H - The attacker writes an unauthorized link key into the host\u0027s persistent bonding database and can then act as a trusted HID keyboard/mouse to inject keystrokes and execute arbitrary commands as the logged-in user, push files via OPP, or drive the device over AVRCP/HFP.\nA:H - As a bonded peer the attacker can hijack and force-disconnect the legitimate input or audio device \u2014 the same \"speaker hijack or mouse/keyboard hijack\" outcome documented for the related bluedump attack \u2014 and HID command injection permits shutting down or otherwise disabling the system."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:44:06.956Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/baaa50c6f91ea5a9c7503af51f2bc50e6568b66b"
        },
        {
          "url": "https://git.kernel.org/stable/c/22b49d6e4f399a390c70f3034f5fbacbb9413858"
        },
        {
          "url": "https://git.kernel.org/stable/c/d17c631ba04e960eb6f8728b10d585de20ac4f71"
        },
        {
          "url": "https://git.kernel.org/stable/c/830c03e58beb70b99349760f822e505ecb4eeb7e"
        },
        {
          "url": "https://git.kernel.org/stable/c/ad7adfb95f64a761e4784381e47bee1a362eb30d"
        },
        {
          "url": "https://git.kernel.org/stable/c/5291ff856d2c5177b4fe9c18828312be30213193"
        },
        {
          "url": "https://git.kernel.org/stable/c/b25e11f978b63cb7857890edb3a698599cddb10e"
        },
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1229/"
        }
      ],
      "title": "Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-53144",
    "datePublished": "2024-12-17T15:55:03.394Z",
    "dateReserved": "2024-11-19T17:17:24.997Z",
    "dateUpdated": "2026-08-05T11:44:06.956Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…