In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcievent: Fix handling of HCIEVIOCAPA_REQUEST
If we received HCIEVIOCAPAREQUEST while HCIOPREADREMOTEEXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1325.0,
"function_hash": "261921581772865092562415592680263556218"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e2758cc25891d2b76717aaf89b40ed215de188c",
"target": {
"file": "net/bluetooth/hci_event.c",
"function": "hci_io_capa_request_evt"
},
"id": "CVE-2024-27416-135064a6"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"95332731043457274065924381105572286028",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@afec8f772296dd8e5a2a6f83bbf99db1b9ca877f",
"target": {
"file": "net/bluetooth/hci_event.c"
},
"id": "CVE-2024-27416-1e594419"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"82450796303787425156360685424424340312",
"127361540383628467528614892399505601525",
"278356059744334327767986585927240072788",
"154201525691118444122498006934900508594",
"160637839839409557411608079446556102493"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e2758cc25891d2b76717aaf89b40ed215de188c",
"target": {
"file": "net/bluetooth/hci_event.c"
},
"id": "CVE-2024-27416-83f35559"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1339.0,
"function_hash": "108704730272158560402736352936545704255"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@afec8f772296dd8e5a2a6f83bbf99db1b9ca877f",
"target": {
"file": "net/bluetooth/hci_event.c",
"function": "hci_io_capa_request_evt"
},
"id": "CVE-2024-27416-ac5fc639"
}
]