CVE-2017-15868
published 2017-12-05CVE-2017-15868: The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
35.7th percentile
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.0.2-1 (bookworm) | linux 4.0.2-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-142.191 | 3.13.0-142.191 |
| linux | linux_kernel | >= 3.11 < 3.16.52 | 3.16.52 |
| linux | linux_kernel | >= 3.17 < 3.18.64 | 3.18.64 |
| linux | linux_kernel | >= 3.2 < 3.2.97 | 3.2.97 |
| linux | linux_kernel | >= 3.3 < 3.10.108 | 3.10.108 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6qcf-qpfw-q4v6: The bnep_add_connection function in net/bluetooth/bnep/core
ghsa_unreviewed·2022-05-13
CVE-2017-15868 [HIGH] CWE-20 GHSA-6qcf-qpfw-q4v6: The bnep_add_connection function in net/bluetooth/bnep/core
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
OSV
linux vulnerabilities
osv·2018-02-23·CVSS 7.8
CVE-2017-0750 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that an out-of-bounds write vulnerability existed in the
Flash-Friendly File System (f2fs) in the Linux kernel. An attacker could
construct a malicious file system that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2017-0750)
It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-0861)
It was discovered that the KVM implementation in the Linux kernel allowed
passthrough of the diagnostic I/O port 0x80. An attacker in a guest VM
could use this to cause a denial of service (system crash) in th
OSV
CVE-2017-15868: The bnep_add_connection function in net/bluetooth/bnep/core
osv·2017-12-05·CVSS 7.8
CVE-2017-15868 [HIGH] CVE-2017-15868: The bnep_add_connection function in net/bluetooth/bnep/core
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-23·CVSS 7.8
CVE-2017-0750 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that an out-of-bounds write vulnerability existed in the
Flash-Friendly File System (f2fs) in the Linux kernel. An attacker could
construct a malicious file system that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2017-0750)
It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-0861)
It was discovered that the KVM implementation in the Linux kernel allowed
passthrough of the diagnostic I/O port 0x80. An attacke
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-02-23·CVSS 7.8
CVE-2017-0750 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3583-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that an out-of-bounds write vulnerability existed in the
Flash-Friendly File System (f2fs) in the Linux kernel. An attacker could
construct a malicious file system that, when mounted, could cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2017-0750)
It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this
Debian
CVE-2017-15868: linux - The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kerne...
vendor_debian·2017·CVSS 7.8
CVE-2017-15868 [HIGH] CVE-2017-15868: linux - The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kerne...
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
Red Hat
kernel: bnep_add_connection does not check if l2cap socket is available allowing privilege escalation
vendor_redhat·2014-12-19·CVSS 7.8
CVE-2017-15868 [HIGH] CWE-391 kernel: bnep_add_connection does not check if l2cap socket is available allowing privilege escalation
kernel: bnep_add_connection does not check if l2cap socket is available allowing privilege escalation
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
It was found that the Bluebooth Network Encapsulation Protocol (BNEP) implementation did not validate the type of second socket passed to the BNEPCONNADD ioctl(), which could lead to memory corruption. A local user with the CAP_NET_ADMIN capability can use this for denial of service (crash or data corruption) or possibly for privilege escalation. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we feel it is unlikely.
Statement: This is
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=71bb99a02b32b4cc4265118e85f6035ca72923f0http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://www.securityfocus.com/bid/102084https://github.com/torvalds/linux/commit/71bb99a02b32b4cc4265118e85f6035ca72923f0https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlhttps://patchwork.kernel.org/patch/9882449/https://source.android.com/security/bulletin/pixel/2017-12-01https://usn.ubuntu.com/3583-1/https://usn.ubuntu.com/3583-2/https://www.debian.org/security/2018/dsa-4082http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=71bb99a02b32b4cc4265118e85f6035ca72923f0http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://www.securityfocus.com/bid/102084https://github.com/torvalds/linux/commit/71bb99a02b32b4cc4265118e85f6035ca72923f0https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlhttps://patchwork.kernel.org/patch/9882449/https://source.android.com/security/bulletin/pixel/2017-12-01https://usn.ubuntu.com/3583-1/https://usn.ubuntu.com/3583-2/https://www.debian.org/security/2018/dsa-4082
2017-12-05
Published