UBUNTU-CVE-2017-1000251
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
02 / AFFECTED SOFTWARE
Affected packages
120 explicit affected versions
38 explicit affected versions
60 explicit affected versions
18 explicit affected versions
6 explicit affected versions
1 explicit affected versions
16 explicit affected versions
20 explicit affected versions
36 explicit affected versions
33 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2017-1000251
- https://ubuntu.com/security/notices/USN-3419-1
- https://ubuntu.com/security/notices/USN-3419-2
- https://ubuntu.com/security/notices/USN-3420-1
- https://ubuntu.com/security/notices/USN-3420-2
- https://ubuntu.com/security/notices/USN-3422-1
- https://ubuntu.com/security/notices/USN-3422-2
- https://ubuntu.com/security/notices/USN-3423-1
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/BlueBorne
- https://www.armis.com/blueborne
- https://www.cve.org/CVERecord?id=CVE-2017-1000251