PT-2017-2790 · Linux+5 · Linux Kernel+5
Alon Livne
·
Published
2017-09-09
·
Updated
2025-09-29
·
CVE-2017-1000251
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel (BlueZ) versions 2.6.32 through 4.13.1
Description
The issue is related to a stack overflow vulnerability in the processing of L2CAP configuration responses, which can result in remote code execution in kernel space. This vulnerability is associated with a buffer overflow in the L2CAP module of the BlueZ package, implementing the Bluetooth protocol stack. Exploitation of this vulnerability allows a remote attacker to control the buffer size and execute arbitrary code.
Recommendations
For Linux Kernel (BlueZ) versions 2.6.32 through 4.13.1, update to a version later than 4.13.1 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific vulnerability.
Exploit
Fix
RCE
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu