CVE-2012-6544
published 2013-03-15CVE-2012-6544: The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.37%
29.0th percentile
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
Affected
167 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.30-1 (bookworm) | linux 3.2.30-1 (bookworm) |
| linux | linux_kernel | <= 3.5.7 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_ubuntu4.9MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-04-25·CVSS 1.9
CVE-2012-6542 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's
getsockname implementation for Logical Link Layer (llc) sockets. A local
user could exploit this flaw to examine some of the kernel's stack memory.
(CVE-2012-6542)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
Logical Link Control and Adaptation Protocol (L2CAP) implementation. A
local user could exploit these flaws to examine some of the kernel's stack
memory. (CVE-2012-6544)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
RFCOMM protocol implementation. A local user could exploit these flaws to
examine parts of kernel memory. (CVE-2012-6545)
Mathias Krause dis
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-19·CVSS 1.9
CVE-2012-6542 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's
getsockname implementation for Logical Link Layer (llc) sockets. A local
user could exploit this flaw to examine some of the kernel's stack memory.
(CVE-2012-6542)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
Logical Link Control and Adaptation Protocol (L2CAP) implementation. A
local user could exploit these flaws to examine some of the kernel's stack
memory. (CVE-2012-6544)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
RFCOMM protocol implementation. A local user could exploit these flaws to
examine parts of kernel memory. (CVE-2012-6545)
Mathias Krause discovere
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of kernel memory. (CVE-2012-6536)
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel m
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of kernel memory. (CVE-2012-6536)
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examin
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of kernel memory. (CVE-2012-6536)
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-10-12·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to perform privileged actions as an administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an information leak in th
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-10-09·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run actions or potentially programs as an
administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an infor
Red Hat
Kernel: Bluetooth: HCI & L2CAP information leaks
vendor_redhat·2012-08-15·CVSS 1.9
CVE-2012-6544 [LOW] Kernel: Bluetooth: HCI & L2CAP information leaks
Kernel: Bluetooth: HCI & L2CAP information leaks
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
Statement: This issue does not affect the version of the kernel package as shipped with
Red Hat Enterprise MRG 2.
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2012-6544: linux - The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly in...
vendor_debian·2012·CVSS 1.9
CVE-2012-6544 [LOW] CVE-2012-6544: linux - The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly in...
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
Scope: local
bookworm: resolved (fixed in 3.2.30-1)
bullseye: resolved (fixed in 3.2.30-1)
forky: resolved (fixed in 3.2.30-1)
sid: resolved (fixed in 3.2.30-1)
trixie: resolved (fixed in 3.2.30-1)
GHSA
GHSA-jxmg-946j-rxw8: The Bluetooth protocol stack in the Linux kernel before 3
ghsa_unreviewed·2022-05-14
CVE-2012-6544 [LOW] CWE-200 GHSA-jxmg-946j-rxw8: The Bluetooth protocol stack in the Linux kernel before 3
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
OSV
CVE-2012-6544: The Bluetooth protocol stack in the Linux kernel before 3
osv·2013-03-15·CVSS 1.9
CVE-2012-6544 [LOW] CVE-2012-6544: The Bluetooth protocol stack in the Linux kernel before 3
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3f68ba07b1da811bf383b4b701b129bfcb2e4988http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=792039c73cf176c8e39a6e8beef2c94ff46522edhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e15ca9a0ef9a86f0477530b0f44a725d67f889eehttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://www.openwall.com/lists/oss-security/2013/03/05/13http://www.ubuntu.com/usn/USN-1805-1http://www.ubuntu.com/usn/USN-1808-1https://github.com/torvalds/linux/commit/3f68ba07b1da811bf383b4b701b129bfcb2e4988https://github.com/torvalds/linux/commit/792039c73cf176c8e39a6e8beef2c94ff46522edhttps://github.com/torvalds/linux/commit/e15ca9a0ef9a86f0477530b0f44a725d67f889eehttps://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3f68ba07b1da811bf383b4b701b129bfcb2e4988http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=792039c73cf176c8e39a6e8beef2c94ff46522edhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e15ca9a0ef9a86f0477530b0f44a725d67f889eehttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://www.openwall.com/lists/oss-security/2013/03/05/13http://www.ubuntu.com/usn/USN-1805-1http://www.ubuntu.com/usn/USN-1808-1https://github.com/torvalds/linux/commit/3f68ba07b1da811bf383b4b701b129bfcb2e4988https://github.com/torvalds/linux/commit/792039c73cf176c8e39a6e8beef2c94ff46522edhttps://github.com/torvalds/linux/commit/e15ca9a0ef9a86f0477530b0f44a725d67f889eehttps://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
2013-03-15
Published