Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()
In the parse_adv_monitor_pattern() function, the value of the ’length’ variable is currently limited to HCI_MAX_EXT_AD_LENGTH(251). The size of the ‘value’ array in the mgmt_adv_pattern structure is 31. If the value of ‘pattern[i].length’ is set in the user space and exceeds 31, the ‘patterns[i].value’ array can be accessed out of bound when copied.
Increasing the size of the ‘value’ array in the ‘mgmt_adv_pattern’ structure will break the userspace. Considering this, and to avoid OOB access revert the limits for ‘offset’ and ’length’ back to the value of HCI_MAX_AD_LENGTH.
Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
Details
- Affected product:
- AlmaLinux 9.2 ESU , TuxCare 9.6 ESU
- Affected packages:
- kernel @ 5.14.0 (+1 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 10 | Released |
22 kernels
|
| AlmaLinux 9 | Released |
67 kernels
|
| AlmaLinux 9.6 ESU | Planned | — |
| Debian 12 | Released |
21 kernels
|
| Debian 13 | Will Not Fix | — |
| Oracle Linux 10 | Released |
23 kernels
|
| Oracle Linux 9 | Released |
69 kernels
|
| RHEL 10 | Released |
25 kernels
|
| RHEL 9 | Released |
69 kernels
|
| Rocky Linux 10 | Released |
17 kernels
|
| Rocky Linux 9 | Released |
56 kernels
|
| Ubuntu 24.04 | Planned | — |
| Ubuntu 24.04 AWS | Planned | — |