{"id":"DEBIAN-CVE-2024-50077","details":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: ISO: Fix multiple init when debugfs is disabled  If bt_debugfs is not created successfully, which happens if either CONFIG_DEBUG_FS or CONFIG_DEBUG_FS_ALLOW_ALL is unset, then iso_init() returns early and does not set iso_inited to true. This means that a subsequent call to iso_init() will result in duplicate calls to proto_register(), bt_sock_register(), etc.  With CONFIG_LIST_HARDENED and CONFIG_BUG_ON_DATA_CORRUPTION enabled, the duplicate call to proto_register() triggers this BUG():    list_add double add: new=ffffffffc0b280d0, prev=ffffffffbab56250,     next=ffffffffc0b280d0.   ------------[ cut here ]------------   kernel BUG at lib/list_debug.c:35!   Oops: invalid opcode: 0000 [#1] PREEMPT SMP PTI   CPU: 2 PID: 887 Comm: bluetoothd Not tainted 6.10.11-1-ao-desktop #1   RIP: 0010:__list_add_valid_or_report+0x9a/0xa0   ...     __list_add_valid_or_report+0x9a/0xa0     proto_register+0x2b5/0x340     iso_init+0x23/0x150 [bluetooth]     set_iso_socket_func+0x68/0x1b0 [bluetooth]     kmem_cache_free+0x308/0x330     hci_sock_sendmsg+0x990/0x9e0 [bluetooth]     __sock_sendmsg+0x7b/0x80     sock_write_iter+0x9a/0x110     do_iter_readv_writev+0x11d/0x220     vfs_writev+0x180/0x3e0     do_writev+0xca/0x100   ...  This change removes the early return. The check for iso_debugfs being NULL was unnecessary, it is always NULL when iso_inited is false.","modified":"2026-09-15T09:02:58.957075199Z","published":"2024-10-29T01:15:04.773Z","upstream":["CVE-2024-50077"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-50077"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.115-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50077.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50077.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50077.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}