Slab-data disclosure via unchecked board-ID response
Published May 30, 2024 · Updated May 11, 2026
Information disclosure in Linux kernel 6.7 through 6.8.9 allows local users to expose slab data during QCA firmware loading. The qca_read_fw_board_id function reads two board-ID bytes from a short controller response without first verifying that the response contains them, then uses the value in a firmware request. Reachability requires an affected kernel and QCA2066 Bluetooth hardware during initialization; the disclosed material is limited to the two slab bytes consumed as the board identifier.
Summary
What happened
Information disclosure in Linux kernel 6.7 through 6.8.9 allows local users to expose slab data during QCA firmware loading. The qca_read_fw_board_id function reads two board-ID bytes from a short controller response without first verifying that the response contains them, then uses the value in a firmware request. Reachability requires an affected kernel and QCA2066 Bluetooth hardware during initialization; the disclosed material is limited to the two slab bytes consumed as the board identifier.
The record
- CVE
- CVE-2024-36033
- Published
- May 30, 2024
- Updated
- May 11, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1005
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- May 30, 2024CVE publishedPublication date reported by the CVE source.
- May 11, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=6.7
- Affected versionversion=a381ee26d7c70dbc048cd17c4e0f40619118ff1f <ba307abed5e09759845c735ba036f8c12f55b209
- Affected versionversion=a7f8dedb4be2cc930a29af24427b885405ecd15d <0adcf6be1445ed50bfd4a451a7a782568f270197
- Affected versionversion=a7f8dedb4be2cc930a29af24427b885405ecd15d <f30c37cb4549baf8377434892d520fe7769bdba7
- Affected versionversion=ad643241d455fdd2516d46cfa54bd0c5e504fc86 <bcccdc947d2ca5972b1e92d0dea10803ddc08ceb
- Affected versionversion=c3c1bd421db6187ee455995bfbf1ba16d98f5e6b <a3dff121a7f5104c4c2d47edaa2351837ef645dd
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo