Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2020-12351

Severity
8.8HIGH
EPSS
2.7%
top 14.07%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 23
Latest updateJan 27

Description

Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages34 packages

CVEListV5bluezSee references
NVDlinux/linux_kernel4.7.74.9.240+6
Debianlinux< 5.9.1-1+3
Ubuntulinux< 4.15.0-122.124+5
Ubuntulinux-hwe< 4.15.0-122.124~16.04.1

🔴Vulnerability Details

13
OSV
linux-xilinx-zynqmp vulnerabilities2025-01-27
OSV
linux-azure, linux-intel-iotg-5.15 vulnerabilities2025-01-09
OSV
linux-azure-5.15 vulnerabilities2025-01-09
OSV
linux-gke vulnerabilities2025-01-07
OSV
linux-intel-iotg vulnerabilities2025-01-06

💥Exploits & PoCs

1
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution2021-04-08

📋Vendor Advisories

13
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2025-01-27
Ubuntu
Linux kernel vulnerabilities2025-01-09
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-09
Ubuntu
Linux kernel (GKE) vulnerabilities2025-01-07
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2025-01-06

💬Community

3
Bugzilla
CVE-2020-25661 kernel: Red Hat only CVE-2020-12351 regression2020-10-26
Bugzilla
CVE-2020-12351 kernel: net: bluetooth: type confusion while processing AMP packets [fedora-all]2020-10-14
Bugzilla
CVE-2020-12351 kernel: net: bluetooth: type confusion while processing AMP packets2020-10-08