CVE-2024-50125

Bluetooth: SCO: Fix UAF on sco_sock_timeout

References

Notes

 carnil> Introduced in ba316be1b6a0 ("Bluetooth: schedule SCO timeouts with
 carnil> delayed_work"). Vulnerable versions: 4.14.263 4.19.207 5.4.148 5.10.67 5.13.19
 carnil> 5.14.6 5.15-rc1.

Bugs

Status

Branch Status
upstream released (6.12-rc5) [1bf4470a3939c678fb822073e9ea77a0560bc6bb]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.11-upstream-stable released (6.11.6) [80b05fbfa998480fb3d5299d93eab946f51e9c36]
6.6-upstream-stable released (6.6.59) [d30803f6a972b5b9e26d1d43b583c7ec151de04b]
6.1-upstream-stable released (6.1.115) [9ddda5d967e84796e7df1b54a55f36b4b9f21079]
5.10-upstream-stable needed
sid released (6.11.6-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.115-1)
5.10-bullseye-security needed