CVE-2024-42132
In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX
CVSS
7.6
Alto
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 30 jul 2024 · Última mod.: 4 ago 2026 · CWE-763
0.3%EPSS · 30 días0.3%
2026-08-102026-09-06
In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caused by handle bigger than HCI_CONN_HANDLE_MAX passed by hci_le_big_sync_established_evt(), which makes code think it's unset connection. Add same check for handle upper bound as in hci_conn_set_handle() to prevent warning.
- git.kernel.orghttps://git.kernel.org/stable/c/1cc18c2ab2e8c54c355ea7c0423a636e415a0c23
- git.kernel.orghttps://git.kernel.org/stable/c/2ae8d7742a09c275872e670c53337b3dcedaa11c
- git.kernel.orghttps://git.kernel.org/stable/c/4970e48f83dbd21d2a6a7cdaaafc2a71f7f45dc4
- git.kernel.orghttps://git.kernel.org/stable/c/d311036696fed778301d08a71a4bef737b86d8c5
- git.kernel.orghttps://git.kernel.org/stable/c/1cc18c2ab2e8c54c355ea7c0423a636e415a0c23
- git.kernel.orghttps://git.kernel.org/stable/c/4970e48f83dbd21d2a6a7cdaaafc2a71f7f45dc4
- git.kernel.orghttps://git.kernel.org/stable/c/d311036696fed778301d08a71a4bef737b86d8c5
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-841318.8 ALT25.6%
——8Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.5dCVE-2023-205116.4 MED14.1%
——4Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.4dCVE-2026-19315—38.2%
——11A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.4dCVE-2026-749478.8 ALT15.5%
——5Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.18dCVE-2026-157184.3 MED40.4%
——12We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.47dCVE-2026-572487.8 ALT6.6%
——2When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.61d