# CVE-2024-38620

## Summary

- **CVE ID:** CVE-2024-38620
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Jun 20, 2024
- **Last Modified:** Aug 23, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: HCI: Remove HCI_AMP support

Since BT_HS has been remove HCI_AMP controllers no longer has any use so
remove it along with the capability of creating AMP controllers.

Since we no longer need to differentiate between AMP and Primary
controllers, as only HCI_PRIMARY is left, this also remove
hdev->dev_type altogether.

## Affected Products

- Linux — Linux (244bc377591c3882f454882357bc730c90cbedb5)
- Linux — Linux (4.3)
- Linux — Linux (0)
- Linux — Linux (6.6.33)
- Linux — Linux (6.8.12)
- Linux — Linux (6.9.3)
- Linux — Linux (6.10)
- Linux — Linux (6.1.184)

## References

- [CNA](https://git.kernel.org/stable/c/5af2e235b0d5b797e9531a00c50058319130e156)
- [CNA](https://git.kernel.org/stable/c/d3c7b012d912b31ad23b9349c0e499d6dddd48ec)
- [CNA](https://git.kernel.org/stable/c/af1d425b6dc67cd67809f835dd7afb6be4d43e03)
- [CNA](https://git.kernel.org/stable/c/84a4bb6548a29326564f0e659fb8064503ecc1c7)
- [CNA](https://git.kernel.org/stable/c/9e6cf0eccfe15b67bf9773ecd101162dfdfed5e2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._