CVE-2017-1000251
Description
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC)
OS impact
Red Hat Affected 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 7.0 | Affected | โ |
| 6.0 | Affected | โ |
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
Debian Mixed 7 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 4.12.13-1 |
| sid | Fixed | 4.12.13-1 |
| forky | Fixed | 4.12.13-1 |
| bullseye | Fixed | 4.12.13-1 |
| bookworm | Fixed | 4.12.13-1 |
| 9.0 | Affected | โ |
| 8.0 | Affected | โ |
Linux kernel Mixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| - | Not affected | โ |
| โ | Affected | 3.2.94 |
Arch Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Fixed | 4.13.1.b-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| nvidia | jetson_tk1 | r21 | |
| nvidia | jetson_tk1 | r24 | |
| nvidia | jetson_tx1 | r21 | |
| nvidia | jetson_tx1 | r24 | |
References
- https://security.archlinux.org/ASA-201709-4
- https://security.archlinux.org/ASA-201709-12
- https://security.archlinux.org/ASA-201709-8
- https://security.archlinux.org/ASA-201709-9
- http://nvidia.custhelp.com/app/answers/detail/a_id/4561
- http://www.debian.org/security/2017/dsa-3981
- http://www.securityfocus.com/bid/100809
- http://www.securitytracker.com/id/1039373
- https://access.redhat.com/errata/RHSA-2017:2679
- https://access.redhat.com/errata/RHSA-2017:2680
- https://access.redhat.com/errata/RHSA-2017:2681
- https://access.redhat.com/errata/RHSA-2017:2682
- https://access.redhat.com/errata/RHSA-2017:2683
- https://access.redhat.com/errata/RHSA-2017:2704
- https://access.redhat.com/errata/RHSA-2017:2705
- https://access.redhat.com/errata/RHSA-2017:2706
- https://access.redhat.com/errata/RHSA-2017:2707
- https://access.redhat.com/errata/RHSA-2017:2731
- https://access.redhat.com/errata/RHSA-2017:2732
- https://access.redhat.com/security/vulnerabilities/blueborne
- https://github.com/torvalds/linux/commit/f2fcfcd670257236ebf2088bbdf26f6a8ef459fe
- https://www.armis.com/blueborne
- https://www.exploit-db.com/exploits/42762/
- https://www.kb.cert.org/vuls/id/240311
- https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne
CWEs
CWE-787
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.