PT-2011-1008 · Linux+2 · Linux Kernel+2

Published

2011-07-15

·

Updated

2023-02-13

·

CVE-2011-2492

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.0-rc4
Description The bluetooth subsystem in the Linux kernel does not properly initialize certain data structures, allowing local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call. This issue is related to the l2cap sock getsockopt old function in net/bluetooth/l2cap sock.c and the rfcomm sock getsockopt old function in net/bluetooth/rfcomm/sock.c.
Recommendations For Linux kernel versions prior to 3.0-rc4, consider updating to version 3.0-rc4 or later to resolve the issue. As a temporary workaround, consider restricting access to the bluetooth subsystem to minimize the risk of exploitation.

Fix

RCE

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2014-00069
CVE-2011-2492
DSA-2303-1
DSA-2310-1
RHSA-2011:0927
RHSA-2011:1189
RHSA-2011:1253
RHSA-2011_0927
RHSA-2011_1189
SUSE-SU-2014_0536-1
USN-1189-1
USN-1201-1
USN-1202-1
USN-1203-1
USN-1204-1
USN-1205-1
USN-1208-1
USN-1211-1
USN-1212-1
USN-1216-1
USN-1218-1
USN-1256-1

Affected Products

Linux Kernel
Red Hat
Suse