{"id":"CVE-2024-35850","summary":"Bluetooth: qca: fix NULL-deref on non-serdev setup","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NULL-deref on non-serdev setup\n\nQualcomm ROME controllers can be registered from the Bluetooth line\ndiscipline and in this case the HCI UART serdev pointer is NULL.\n\nAdd the missing sanity check to prevent a NULL-pointer dereference when\nsetup() is called for a non-serdev controller.","modified":"2026-04-16T04:37:09.226266585Z","published":"2024-05-17T14:47:28.139Z","related":["SUSE-SU-2024:2135-1","SUSE-SU-2024:2203-1","SUSE-SU-2024:2973-1","SUSE-SU-2025:20008-1","SUSE-SU-2025:20028-1","SUSE-SU-2025:20166-1","SUSE-SU-2025:20249-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35850.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/67459f1a707aae6d590454de07956c2752e21ea4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7ddb9de6af0f1c71147785b12fd7c8ec3f06cc86"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bec4d4c6fa5c6526409f582e4f31144e20c86c21"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35850.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35850"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"e9b3e5b8c65733f626a7ee919c4bc895b51d7bb2"},{"fixed":"67459f1a707aae6d590454de07956c2752e21ea4"},{"fixed":"bec4d4c6fa5c6526409f582e4f31144e20c86c21"},{"fixed":"7ddb9de6af0f1c71147785b12fd7c8ec3f06cc86"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-35850.json"}}],"schema_version":"1.7.5"}