CVE-2024-27398PoC(debian / debian_linux)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for debian debian_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated later, but it is dereferenced again in sco_sock_timeout. As a result, the use-after-free bugs will happen. The root cause is shown below: Cleanup Thread | Worker Thread sco_sock_release | sco_sock_close | __sco_sock_close | sco_sock_set_timer | schedule_delayed_work | sco_sock_kill | (wait a time) sock_put(sk) //FREE | sco_sock_timeout | sock_hold(sk) //USE The KASAN report triggered by POC is shown below: [ 95.890016] ================================================================== [ 95.890496] BUG: KASAN: slab-use-after-free in sco_sock_timeout+0x5e/0x1c0 [ 95.890755] Write of size 4 at addr ffff88800c388080 by task kworker/0:0/7 ... [ 95.890755] Workqueue: events sco_sock_timeout [ 95.890755] Call Trace: [ 95.890755] <TASK> [ 95.890755] dump_stack_lvl+0x45/0x110 [ 95.890755] print_address_description+0x78/0x390 [ 95.890755] print_report+0x11b/0x250 [ 95.890755] ? __virt_addr_valid+0xbe/0xf0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_report+0x139/0x170 [ 95.890755] ? update_load_avg+0xe5/0x9f0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_check_range+0x2c3/0x2e0 [ 95.890755] sco_sock_timeout+0x5e/0x1c0 [ 95.890755] process_one_work+0x561/0xc50 [ 95.890755] worker_thread+0xab2/0x13c0 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] kthread+0x279/0x300 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork+0x34/0x60 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork_asm+0x11/0x20 [ 95.890755] </TASK> [ 95.890755] [ 95.890755] Allocated by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] __kasan_kmalloc+0x86/0x90 [ 95.890755] __kmalloc+0x17f/0x360 [ 95.890755] sk_prot_alloc+0xe1/0x1a0 [ 95.890755] sk_alloc+0x31/0x4e0 [ 95.890755] bt_sock_alloc+0x2b/0x2a0 [ 95.890755] sco_sock_create+0xad/0x320 [ 95.890755] bt_sock_create+0x145/0x320 [ 95.890755] __sock_create+0x2e1/0x650 [ 95.890755] __sys_socket+0xd0/0x280 [ 95.890755] __x64_sys_socket+0x75/0x80 [ 95.890755] do_syscall_64+0xc4/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] Freed by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] kasan_save_free_info+0x40/0x50 [ 95.890755] poison_slab_object+0x118/0x180 [ 95.890755] __kasan_slab_free+0x12/0x30 [ 95.890755] kfree+0xb2/0x240 [ 95.890755] __sk_destruct+0x317/0x410 [ 95.890755] sco_sock_release+0x232/0x280 [ 95.890755] sock_close+0xb2/0x210 [ 95.890755] __fput+0x37f/0x770 [ 95.890755] task_work_run+0x1ae/0x210 [ 95.890755] get_signal+0xe17/0xf70 [ 95.890755] arch_do_signal_or_restart+0x3f/0x520 [ 95.890755] syscall_exit_to_user_mode+0x55/0x120 [ 95.890755] do_syscall_64+0xd1/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] The buggy address belongs to the object at ffff88800c388000 [ 95.890755] which belongs to the cache kmalloc-1k of size 1024 [ 95.890755] The buggy address is located 128 bytes inside of [ 95.890755] freed 1024-byte region [ffff88800c388000, ffff88800c388400) [ 95.890755] [ 95.890755] The buggy address belongs to the physical page: [ 95.890755] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88800c38a800 pfn:0xc388 [ 95.890755] head: order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 95.890755] ano ---truncated---

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • fedora
  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 3 signals
  • Peaked 3d ago at 2 mentions (2026-03-30); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
debian_linuxfedoralinux_kernel

4 versions affected across 3 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-30: 2Mentions · 2026-04-04: 1Mentions · 2026-04-27: 1Mentions · 2026-05-24: 1PoC Mentioned / Linked · 2026-03-30: 2PoC Mentioned / Linked · 2026-04-04: 1PoC Mentioned / Linked · 2026-05-24: 1Exploit Tool / Code · 2026-03-30: 1Exploit Tool / Code · 2026-04-04: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-24: 103-3004-0404-2705-24
Signal classification2 categories
PoC
360.0%
Exploit
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-302
PoC2
2026-04-041
Exploit1
2026-04-271
Exploit1
2026-05-241
PoC1
Full discourse5 posts
  • NullSecurityX@NullSecurityX
    PoC

    From a tiny race condition in Linux Bluetooth SCO to a full kernel LPE. The Secunnix team dissected the vulnerable path, engineered a heap spray + SMEP bypass, and turned a subtle UAF into reliable uid=0 execution all demonstrated on real QEMU/KVM runs. https://scnx.com/blog/cve-2024-27398-exploiting-a-linux-bluetooth-sco-use-after-free-with-smep-bypass

    Post summary

    The text announces a detailed PoC for CVE-2024-27398, describing exploitation of a Linux Bluetooth SCO UAF vulnerability with heap spray and SMEP bypass techniques, resulting in kernel LPE, and links to a blog post with full technical details.

    09036213.4K
    12.3K followersView on X
  • Safa Karakuş@sfkarakus
    PoC

    @0x94 katkılarıyla https://github.com/secunnix/CVE-2024-27398/blob/main/poc_rip_overwrite.c

    Post summary

    A link to a GitHub proof‑of‑concept file for CVE‑2024‑27398 is provided, indicating availability of a PoC exploit code but no evidence of active exploitation, patches, or technical details.

    010153655
    852 followersView on X
  • Secunnix@secunnix
    Exploit

    CVE-2024-27398 - Exploiting a Linux Bluetooth SCO Use-After-Free with SMEP Bypass https://scnx.com/blog/cve-2024-27398-exploiting-a-linux-bluetooth-sco-use-after-free-with-smep-bypass

    Post summary

    The post announces exploitation of CVE‑2024‑27398 via a Use‑After‑Free in Linux Bluetooth SCO, detailing the SMEP bypass technique but providing no patches, active exploitation reports, or PoC links.

    020121778
    374 followersView on X
  • Safa Karakuş@sfkarakus
    Exploit

    === CVE-2024-27398 LPE (SMEP BYPASS) === [+] Pivot page at 0x81011000, ROP at 0x81011cf1 [*] HCI ready [*] Waiting 3s... [*] No luck [*] Batch 1 [*] Waiting 3s... [*] No luck [*] Batch 2 [*] Waiting 3s... [*] No luck [*] Batch 3 [*] /tmp/pwn: uid=0 gid=0 ROOTED https://t.co/mTdvaqVMvo

    Post summary

    The snippet demonstrates a successful local privilege escalation on CVE‑2024‑27398 via an SMEP bypass, confirming a working exploit chain that achieves root.

    1101121.2K
    847 followersView on X
  • Safa Karakuş@sfkarakus
    PoC

    https://github.com/secunnix/CVE-2024-27398/blob/main/poc_rip_overwrite.c

    Post summary

    The post includes a link to a PoC code file for CVE-2024-27398, confirming the existence of a proof‑of‑concept but no other exploitation or mitigation details.

    0000025
    848 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSfedoraprojectfedora39--
OSfedoraprojectfedora40--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.9--
OSlinuxlinux_kernel6.9--
OSlinuxlinux_kernel6.9--
OSlinuxlinux_kernel6.9--
OSlinuxlinux_kernel6.9--
OSlinuxlinux_kernel6.9--
OSlinuxlinux_kernel6.9--

Explore more