FlawAtlas
Search the atlas
USN-6973-1 Not scored

linux, linux-aws, linux-azure, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-xilinx-zynqmp vulnerabilities

It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A privileged local attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-24860) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SuperH RISC architecture; - MMC subsystem; - Network drivers; - SCSI drivers; - GFS2 file system; - IPv4 networking; - IPv6 networking; - HD-audio driver; (CVE-2024-26830, CVE-2024-39484, CVE-2024-36901, CVE-2024-26929, CVE-2024-26921, CVE-2021-46926, CVE-2023-52629, CVE-2023-52760)

Exploit probability Not scored
Published August 21, 2024
Required by Not available
Last source change August 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:20.04:LTS linux

104 explicit affected versions

Ubuntu:20.04:LTS linux-aws

96 explicit affected versions

Ubuntu:20.04:LTS linux-azure

92 explicit affected versions

Ubuntu:20.04:LTS linux-bluefield

55 explicit affected versions

Ubuntu:20.04:LTS linux-gcp

96 explicit affected versions

Ubuntu:20.04:LTS linux-gkeop

73 explicit affected versions

Ubuntu:20.04:LTS linux-ibm

61 explicit affected versions

Ubuntu:20.04:LTS linux-kvm

91 explicit affected versions

Ubuntu:20.04:LTS linux-oracle

94 explicit affected versions

Ubuntu:20.04:LTS linux-raspi

84 explicit affected versions

Ubuntu:20.04:LTS linux-xilinx-zynqmp

30 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-gcp-5.4

84 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-hwe-5.4

93 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-ibm-5.4

54 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-oracle-5.4

83 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-6973-1

It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A privileged local attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-24860) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SuperH RISC architecture; - MMC subsystem; - Network drivers; - SCSI drivers; - GFS2 file system; - IPv4 networking; - IPv6 networking; - HD-audio driver; (CVE-2024-26830, CVE-2024-39484, CVE-2024-36901, CVE-2024-26929, CVE-2024-26921, CVE-2021-46926, CVE-2023-52629, CVE-2023-52760)

View original source

05 / REFERENCES

Further evidence