You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2024 26903
About this tag
CVE-2024-26903 is a Linux kernel vulnerability in the Bluetooth RFCOMM subsystem that can be exploited to cause a denial-of-service condition. The flaw is a null-pointer dereference in the rfcomm_check_security path, triggered when an out-of-order HCI response arrives during connection teardown. This leads to a kernel panic, crashing the host system. The vulnerability affects the RFCOMM serial-port emulation layer over Bluetooth's L2CAP transport, commonly used by legacy serial-over-Bluetooth applications and embedded stacks. A targeted patch has been released to fix the race condition and prevent the null-pointer dereference. Users are advised to apply the update to mitigate the risk of system crashes.
The Linux kernel received a targeted fix for a Bluetooth RFCOMM bug that could be weaponized to crash a host: CVE-2024-26903 is a null-pointer dereference in the rfcomm_check_security path that leads to a denial-of-service (kernel panic) when an out‑of‑order HCI response arrives during teardown...