Answer in brief
CVE-2024-27416 records a Unknown severity vulnerability in Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-27416 records a Unknown severity vulnerability in Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ccb8618c972f941ebc6b2b9db491025b3369efcb <afec8f772296dd8e5a2a6f83bbf99db1b9ca877f || >=1769ac55dbf3114d5bf79f11bd5dca80ee263f9c <79820a7e1e057120c49be07cbe10643d0706b259 || >=40a33a129d99639921ce00d274cca44ba282f1ac <df193568d61234c81de7ed4d540c01975de60277 || >=1ef071526848cc3109ade63268854cd7c20ece0c <c3df637266df29edee85e94cab5fd7041e5753ba || >=25e5d2883002e235f3378b8592aad14aeeef898c <30a5e812f78e3d1cced90e1ed750bf027599205f || >=c7f59461f5a78994613afc112cdd73688aef9076 <fba268ac36ab19f9763ff90d276cde0ce6cd5f31 || >=c7f59461f5a78994613afc112cdd73688aef9076 <8e2758cc25891d2b76717aaf89b40ed215de188c || >=c7f59461f5a78994613afc112cdd73688aef9076 <7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865 || 2c7f9fda663a1b31a61744ffc456bdb89c4efc7f || 746dbb0fc6392eca23de27f8aa9d13979b564889 || >=4.19.297 <4.19.309 || >=5.4.259 <5.4.271 || >=5.10.199 <5.10.212 || >=5.15.137 <5.15.151 || >=6.1.60 <6.1.81 || >=4.14.328 <4.15 || >=6.5.9 <6.6 | afec8f772296dd8e5a2a6f83bbf99db1b9ca877f, 79820a7e1e057120c49be07cbe10643d0706b259, df193568d61234c81de7ed4d540c01975de60277, c3df637266df29edee85e94cab5fd7041e5753ba, 30a5e812f78e3d1cced90e1ed750bf027599205f, fba268ac36ab19f9763ff90d276cde0ce6cd5f31, 8e2758cc25891d2b76717aaf89b40ed215de188c, 7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865, 4.19.309, 5.4.271, 5.10.212, 5.15.151, 6.1.81, 4.15, 6.6 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
May 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ccb8618c972f941ebc6b2b9db491025b3369efcb <afec8f772296dd8e5a2a6f83bbf99db1b9ca877f || >=1769ac55dbf3114d5bf79f11bd5dca80ee263f9c <79820a7e1e057120c49be07cbe10643d0706b259 || >=40a33a129d99639921ce00d274cca44ba282f1ac <df193568d61234c81de7ed4d540c01975de60277 || >=1ef071526848cc3109ade63268854cd7c20ece0c <c3df637266df29edee85e94cab5fd7041e5753ba || >=25e5d2883002e235f3378b8592aad14aeeef898c <30a5e812f78e3d1cced90e1ed750bf027599205f || >=c7f59461f5a78994613afc112cdd73688aef9076 <fba268ac36ab19f9763ff90d276cde0ce6cd5f31 || >=c7f59461f5a78994613afc112cdd73688aef9076 <8e2758cc25891d2b76717aaf89b40ed215de188c || >=c7f59461f5a78994613afc112cdd73688aef9076 <7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865 || 2c7f9fda663a1b31a61744ffc456bdb89c4efc7f || 746dbb0fc6392eca23de27f8aa9d13979b564889 || >=4.19.297 <4.19.309 || >=5.4.259 <5.4.271 || >=5.10.199 <5.10.212 || >=5.15.137 <5.15.151 || >=6.1.60 <6.1.81 || >=4.14.328 <4.15 || >=6.5.9 <6.6 | afec8f772296dd8e5a2a6f83bbf99db1b9ca877f, 79820a7e1e057120c49be07cbe10643d0706b259, df193568d61234c81de7ed4d540c01975de60277, c3df637266df29edee85e94cab5fd7041e5753ba, 30a5e812f78e3d1cced90e1ed750bf027599205f, fba268ac36ab19f9763ff90d276cde0ce6cd5f31, 8e2758cc25891d2b76717aaf89b40ed215de188c, 7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865, 4.19.309, 5.4.271, 5.10.212, 5.15.151, 6.1.81, 4.15, 6.6 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
May 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.
Quoted source text, attributed separately from HOL analysis.