CVE-2017-1000410Sensitive Information Exposure in Kernel

Severity
7.5HIGHNVD
CNA8.0OSV8.0
EPSS
1.9%
top 16.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateMay 14

Description

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of these configuration messages, an attacker can also gain some control over which data will be held in the uninitialized stack variables. This can

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

NVDlinux/linux_kernel< 4.15+1
Debianlinux/linux_kernel< 4.14.7-1+3
Ubuntulinux/linux_kernel< 3.13.0-168.218

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.6, 7.4

Patches

🔴Vulnerability Details

5
GHSA
GHSA-6jqp-hcfj-vjh3: The Linux kernel version 32022-05-14
OSV
linux vulnerabilities2019-04-02
Kernel
Bluetooth: Prevent stack info leak from the EFS element.2017-12-08
OSV
CVE-2017-1000410: The Linux kernel version 32017-12-07
CVEList
CVE-2017-1000410: The Linux kernel version 32017-12-07

📋Vendor Advisories

4
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Red Hat
kernel: Stack information leak in the EFS element2017-12-06
Debian
CVE-2017-1000410: linux - The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies i...2017

💬Community

2
Bugzilla
CVE-2017-1000410 kernel: Stack information leak in the EFS element [fedora-all]2017-12-06
Bugzilla
CVE-2017-1000410 kernel: Stack information leak in the EFS element2017-11-30
CVE-2017-1000410 — Sensitive Information Exposure | cvebase