CVE-2024-35850

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-35850
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-35850.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-35850
Downstream
Related
Published
2024-05-17T15:15:21Z
Modified
2025-08-09T19:01:27Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: qca: fix NULL-deref on non-serdev setup

Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL.

Add the missing sanity check to prevent a NULL-pointer dereference when setup() is called for a non-serdev controller.

References

Affected packages