Answer in brief
CVE-2024-35967 records a Unknown severity vulnerability in Bluetooth: SCO: Fix not validating setsockopt user input. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-35967 records a Unknown severity vulnerability in Bluetooth: SCO: Fix not validating setsockopt user input. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b96e9c671b05f95126753a22145d4509d45ca197 <b0e30c37695b614bee69187f86eaf250e36606ce || >=b96e9c671b05f95126753a22145d4509d45ca197 <2c2dc87cdebef3fe3b9d7a711a984c70e376e32e || >=b96e9c671b05f95126753a22145d4509d45ca197 <7bc65d23ba20dcd7ecc094a12c181e594e5eb315 || >=b96e9c671b05f95126753a22145d4509d45ca197 <72473db90900da970a16ee50ad23c2c38d107d8c || >=b96e9c671b05f95126753a22145d4509d45ca197 <419a0ffca7010216f0fc265b08558d7394fa0ba7 || >=b96e9c671b05f95126753a22145d4509d45ca197 <51eda36d33e43201e7a4fd35232e069b2c850b01 | b0e30c37695b614bee69187f86eaf250e36606ce, 2c2dc87cdebef3fe3b9d7a711a984c70e376e32e, 7bc65d23ba20dcd7ecc094a12c181e594e5eb315, 72473db90900da970a16ee50ad23c2c38d107d8c, 419a0ffca7010216f0fc265b08558d7394fa0ba7, 51eda36d33e43201e7a4fd35232e069b2c850b01 |
| Linux/Linuxgeneric | 3.8 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
May 20, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix not validating setsockopt user input syzbot reported sco_sock_setsockopt() is copying data without checking user input length. BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in sco_sock_setsockopt+0xc0b/0xf90 net/bluetooth/sco.c:893 Read of size 4 at addr ffff88805f7b15a3 by task syz-executor.5/12578
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b96e9c671b05f95126753a22145d4509d45ca197 <b0e30c37695b614bee69187f86eaf250e36606ce || >=b96e9c671b05f95126753a22145d4509d45ca197 <2c2dc87cdebef3fe3b9d7a711a984c70e376e32e || >=b96e9c671b05f95126753a22145d4509d45ca197 <7bc65d23ba20dcd7ecc094a12c181e594e5eb315 || >=b96e9c671b05f95126753a22145d4509d45ca197 <72473db90900da970a16ee50ad23c2c38d107d8c || >=b96e9c671b05f95126753a22145d4509d45ca197 <419a0ffca7010216f0fc265b08558d7394fa0ba7 || >=b96e9c671b05f95126753a22145d4509d45ca197 <51eda36d33e43201e7a4fd35232e069b2c850b01 | b0e30c37695b614bee69187f86eaf250e36606ce, 2c2dc87cdebef3fe3b9d7a711a984c70e376e32e, 7bc65d23ba20dcd7ecc094a12c181e594e5eb315, 72473db90900da970a16ee50ad23c2c38d107d8c, 419a0ffca7010216f0fc265b08558d7394fa0ba7, 51eda36d33e43201e7a4fd35232e069b2c850b01 |
| Linux/Linuxgeneric | 3.8 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
May 20, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix not validating setsockopt user input syzbot reported sco_sock_setsockopt() is copying data without checking user input length. BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in sco_sock_setsockopt+0xc0b/0xf90 net/bluetooth/sco.c:893 Read of size 4 at addr ffff88805f7b15a3 by task syz-executor.5/12578
Quoted source text, attributed separately from HOL analysis.