CVE-2024-38620

Executive Summary

CVE-2024-38620 addresses a code removal in the Linux kernel’s Bluetooth stack: the HCI_AMP support and AMP controller creation capability are eliminated, along with the hdev->dev_type field. This change consolidates controller handling to only HCI_PRIMARY, simplifying the HCI interface and removing unused AMP functionality. The patch does not introduce new functionality but cleans up legacy code, reducing attack surface and potential maintenance issues.


Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2024-06-20T08:15:38.377 - Last Modified: 2026-08-23T13:16:24.440

Original Description: In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: HCI: Remove HCI_AMP support

Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP controllers.

Since we no longer need to differentiate between AMP and Primary controllers, as only HCI_PRIMARY is left, this also remove hdev->dev_type altogether.

"If we are facing in the right direction, all we have to do is keep on walking."

— Unknown
Source: NVD