cbcvebase.
CVE-2017-1000251
published 2017-09-12

CVE-2017-1000251: The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack…

high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EXPLOIT
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

Affected

57 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.14.7-1 (bookworm)linux 4.14.7-1 (bookworm)
debianlinux< linux 4.12.13-1 (bookworm)linux 4.12.13-1 (bookworm)
linuxlinux_kernel< 4.154.15
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 4.14.7-14.14.7-1
linuxlinux_kernel>= 0 < 4.12.13-14.12.13-1
linuxlinux_kernel>= 0 < 3.13.0-132.1813.13.0-132.181
linuxlinux_kernel>= 0 < 4.4.0-96.1194.4.0-96.119
linuxlinux_kernel>= 2.6.32 < 3.2.943.2.94
linuxlinux_kernel>= 3.17 < 3.18.713.18.71
linuxlinux_kernel>= 3.19 < 4.1.454.1.45
linuxlinux_kernel>= 3.3 < 3.16.493.16.49
linuxlinux_kernel>= 4.10 < 4.12.134.12.13
linuxlinux_kernel>= 4.13 < 4.13.24.13.2
linuxlinux_kernel>= 4.2 < 4.4.884.4.88
linuxlinux_kernel>= 4.5 < 4.9.504.9.50
nvidiajetson_tk1

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv8.0HIGH