In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hcievent: Align BR/EDR JUSTWORKS paring with LE
This aligned BR/EDR JUSTWORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always request user confirmation with confirmhint set since the likes of bluetoothd have dedicated policy around JUST_WORKS method (e.g. main.conf:JustWorksRepairing).
CVE: CVE-2024-8805
[
{
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"line_hashes": [
"297086557877806741873497723575861595143",
"204548996458462090209592281063073116418",
"102280478116464601048300973408413236849",
"260548172325481819223468948726674824521",
"190470183542941094514803000241565844440",
"280401209888861081926957261050963436476",
"242475144997689979064381256823113841629",
"45878772483012556733096779008873408565"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@830c03e58beb70b99349760f822e505ecb4eeb7e",
"deprecated": false,
"id": "CVE-2024-53144-15dc9c63",
"signature_type": "Line"
},
{
"target": {
"function": "hci_user_confirm_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1681.0,
"function_hash": "289563024825828212039193197263877430035"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@22b49d6e4f399a390c70f3034f5fbacbb9413858",
"deprecated": false,
"id": "CVE-2024-53144-32086d5f",
"signature_type": "Function"
},
{
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"line_hashes": [
"297086557877806741873497723575861595143",
"204548996458462090209592281063073116418",
"102280478116464601048300973408413236849",
"260548172325481819223468948726674824521",
"190470183542941094514803000241565844440",
"280401209888861081926957261050963436476",
"242475144997689979064381256823113841629",
"45878772483012556733096779008873408565"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ad7adfb95f64a761e4784381e47bee1a362eb30d",
"deprecated": false,
"id": "CVE-2024-53144-33d8e5f9",
"signature_type": "Line"
},
{
"target": {
"function": "hci_user_confirm_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1681.0,
"function_hash": "289563024825828212039193197263877430035"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@baaa50c6f91ea5a9c7503af51f2bc50e6568b66b",
"deprecated": false,
"id": "CVE-2024-53144-47f1f7c2",
"signature_type": "Function"
},
{
"target": {
"function": "hci_user_confirm_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1683.0,
"function_hash": "180070140896832148058051797856474785341"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b25e11f978b63cb7857890edb3a698599cddb10e",
"deprecated": false,
"id": "CVE-2024-53144-5c375749",
"signature_type": "Function"
},
{
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"line_hashes": [
"297086557877806741873497723575861595143",
"204548996458462090209592281063073116418",
"102280478116464601048300973408413236849",
"260548172325481819223468948726674824521",
"190470183542941094514803000241565844440",
"55663109774401558119568673125829036965",
"84762041152658620071310442046871101348",
"119574139420404905547561806654515746917"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@baaa50c6f91ea5a9c7503af51f2bc50e6568b66b",
"deprecated": false,
"id": "CVE-2024-53144-5d6b9141",
"signature_type": "Line"
},
{
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"line_hashes": [
"297086557877806741873497723575861595143",
"204548996458462090209592281063073116418",
"102280478116464601048300973408413236849",
"260548172325481819223468948726674824521",
"190470183542941094514803000241565844440",
"280401209888861081926957261050963436476",
"242475144997689979064381256823113841629",
"45878772483012556733096779008873408565"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b25e11f978b63cb7857890edb3a698599cddb10e",
"deprecated": false,
"id": "CVE-2024-53144-5effc769",
"signature_type": "Line"
},
{
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"line_hashes": [
"297086557877806741873497723575861595143",
"204548996458462090209592281063073116418",
"102280478116464601048300973408413236849",
"260548172325481819223468948726674824521",
"190470183542941094514803000241565844440",
"280401209888861081926957261050963436476",
"242475144997689979064381256823113841629",
"45878772483012556733096779008873408565"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5291ff856d2c5177b4fe9c18828312be30213193",
"deprecated": false,
"id": "CVE-2024-53144-75b4a81e",
"signature_type": "Line"
},
{
"target": {
"function": "hci_user_confirm_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1683.0,
"function_hash": "180070140896832148058051797856474785341"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5291ff856d2c5177b4fe9c18828312be30213193",
"deprecated": false,
"id": "CVE-2024-53144-796883f4",
"signature_type": "Function"
},
{
"target": {
"function": "hci_user_confirm_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1683.0,
"function_hash": "180070140896832148058051797856474785341"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d17c631ba04e960eb6f8728b10d585de20ac4f71",
"deprecated": false,
"id": "CVE-2024-53144-9be6f694",
"signature_type": "Function"
},
{
"target": {
"function": "hci_user_confirm_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1683.0,
"function_hash": "180070140896832148058051797856474785341"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ad7adfb95f64a761e4784381e47bee1a362eb30d",
"deprecated": false,
"id": "CVE-2024-53144-ca213465",
"signature_type": "Function"
},
{
"target": {
"function": "hci_user_confirm_request_evt",
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"length": 1683.0,
"function_hash": "180070140896832148058051797856474785341"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@830c03e58beb70b99349760f822e505ecb4eeb7e",
"deprecated": false,
"id": "CVE-2024-53144-e7b80205",
"signature_type": "Function"
},
{
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"line_hashes": [
"297086557877806741873497723575861595143",
"204548996458462090209592281063073116418",
"102280478116464601048300973408413236849",
"260548172325481819223468948726674824521",
"190470183542941094514803000241565844440",
"280401209888861081926957261050963436476",
"242475144997689979064381256823113841629",
"45878772483012556733096779008873408565"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d17c631ba04e960eb6f8728b10d585de20ac4f71",
"deprecated": false,
"id": "CVE-2024-53144-f1874f65",
"signature_type": "Line"
},
{
"target": {
"file": "net/bluetooth/hci_event.c"
},
"digest": {
"line_hashes": [
"297086557877806741873497723575861595143",
"204548996458462090209592281063073116418",
"102280478116464601048300973408413236849",
"260548172325481819223468948726674824521",
"190470183542941094514803000241565844440",
"55663109774401558119568673125829036965",
"84762041152658620071310442046871101348",
"119574139420404905547561806654515746917"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@22b49d6e4f399a390c70f3034f5fbacbb9413858",
"deprecated": false,
"id": "CVE-2024-53144-f63e65f8",
"signature_type": "Line"
}
]