CVE-2017-1000251: Buffer Overflow
An attacker within bluetooth transmission range can cause a stack buffer overflow in the Bluetooth system of the Linux kernel while processing pending L2CAP configuration responses from a client. An unauthenticated user able to connect to a system via Bluetooth could use this flaw to potentially execute arbitrary code with root privileges on the system.
External References:
https://www.armis.com/blueborne/ https://access.redhat.com/security/vulnerabilities/blueborne https://access.redhat.com/solutions/3177231 https://access.redhat.com/blogs/product-security/posts/blueborne
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e860d2c904d1a9f38a24eb44c9f34b8f915a6ea3
Other sources
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000251?
CVE-2017-1000251 is classified with a high severity due to its ability to result in a stack buffer overflow in the Linux kernel Bluetooth system.
How do I fix CVE-2017-1000251?
To fix CVE-2017-1000251, upgrade to the appropriate patched versions of the Linux kernel listed in the vulnerability details.
What systems are affected by CVE-2017-1000251?
CVE-2017-1000251 affects multiple versions of the Linux kernel and Debian GNU/Linux systems as well as certain NVIDIA Jetson devices.
Can attackers exploit CVE-2017-1000251 remotely?
Yes, attackers within Bluetooth transmission range can exploit CVE-2017-1000251 to execute arbitrary code.
Is there a known exploit for CVE-2017-1000251?
While specific exploit code for CVE-2017-1000251 may not be publicly available, the nature of the vulnerability allows for potential exploitation given the right conditions.