CVE-2020-25661

CWE-8437 documents7 sources
Severity
8.8HIGH
EPSS
1.6%
top 18.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 5
Latest updateMay 24

Description

A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. This flaw allows a remote attacker in an adjacent range to crash the system, causing a denial of service or potentially executing arbitrary code on the system by sending a specially crafted L2CAP packet. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages1 packages

CVEListV5red_hat/kernelkernel-4.18.0-240.el8

Also affects: Enterprise Linux 8.3

🔴Vulnerability Details

3
GHSA
GHSA-5jpw-97pv-5g28: A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID2022-05-24
OSV
CVE-2020-25661: A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID2020-11-05
CVEList
CVE-2020-25661: A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID2020-11-05

📋Vendor Advisories

2
Red Hat
kernel: Red Hat only CVE-2020-12351 regression2020-11-03
Debian
CVE-2020-25661: linux - A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux ke...2020

💬Community

1
Bugzilla
CVE-2020-25661 kernel: Red Hat only CVE-2020-12351 regression2020-10-26