CVE-2020-25662
published 2020-11-05CVE-2020-25662: A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack…
PriorityP432medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
1.17%
63.8th percentile
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6v9p-cxvf-8f7v: A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of st
ghsa_unreviewed·2022-05-24·CVSS 6.5
CVE-2020-25662 [MEDIUM] CWE-200 GHSA-6v9p-cxvf-8f7v: A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of st
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.
OSV
CVE-2020-25662: A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of st
osv·2020-11-05·CVSS 6.5
CVE-2020-25662 [MEDIUM] CVE-2020-25662: A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of st
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.
Red Hat
kernel: Red Hat only CVE-2020-12352 regression
vendor_redhat·2020-11-03·CVSS 6.5
CVE-2020-25662 [MEDIUM] CWE-665 kernel: Red Hat only CVE-2020-12352 regression
kernel: Red Hat only CVE-2020-12352 regression
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted
Debian
CVE-2020-25662: linux - A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux ke...
vendor_debian·2020·CVSS 6.5
CVE-2020-25662 [MEDIUM] CVE-2020-25662: linux - A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux ke...
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2020-12352https://access.redhat.com/security/vulnerabilities/BleedingToothhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25662https://access.redhat.com/security/cve/CVE-2020-12352https://access.redhat.com/security/vulnerabilities/BleedingToothhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25662
2020-11-05
Published