Answer in brief
CVE-2024-36032 records a Unknown severity vulnerability in Bluetooth: qca: fix info leak when fetching fw build id. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <62d5550ab62042dcceaf18844d0feadbb962cffe || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <57062aa13e87b1a78a4a8f6cb5fab6ba24f5f488 || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <6b63e0ef4d3ce0080395e5091fba2023f246c45a || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <a571044cc0a0c944e7c12237b6768aeedd7480e1 || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <cda0d6a198e2a7ec6f176c36173a57bdd8af7af2 | 62d5550ab62042dcceaf18844d0feadbb962cffe, 57062aa13e87b1a78a4a8f6cb5fab6ba24f5f488, 6b63e0ef4d3ce0080395e5091fba2023f246c45a, a571044cc0a0c944e7c12237b6768aeedd7480e1, cda0d6a198e2a7ec6f176c36173a57bdd8af7af2 |
| Linux/Linuxgeneric | 5.12 | Not reported |
Published upstream
May 30, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case the build-info reply is malformed.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-36032 records a Unknown severity vulnerability in Bluetooth: qca: fix info leak when fetching fw build id. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <62d5550ab62042dcceaf18844d0feadbb962cffe || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <57062aa13e87b1a78a4a8f6cb5fab6ba24f5f488 || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <6b63e0ef4d3ce0080395e5091fba2023f246c45a || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <a571044cc0a0c944e7c12237b6768aeedd7480e1 || >=c0187b0bd3e94c48050687d87b2c3c9fbae98ae9 <cda0d6a198e2a7ec6f176c36173a57bdd8af7af2 | 62d5550ab62042dcceaf18844d0feadbb962cffe, 57062aa13e87b1a78a4a8f6cb5fab6ba24f5f488, 6b63e0ef4d3ce0080395e5091fba2023f246c45a, a571044cc0a0c944e7c12237b6768aeedd7480e1, cda0d6a198e2a7ec6f176c36173a57bdd8af7af2 |
| Linux/Linuxgeneric | 5.12 | Not reported |
Published upstream
May 30, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case the build-info reply is malformed.
Quoted source text, attributed separately from HOL analysis.