CVE-2017-1000251: Buffer Overflow

Published Sep 8, 2017
·
Updated

An attacker within bluetooth transmission range can cause a stack buffer overflow in the Bluetooth system of the Linux kernel while processing pending L2CAP configuration responses from a client. An unauthenticated user able to connect to a system via Bluetooth could use this flaw to potentially execute arbitrary code with root privileges on the system.

External References:

https://www.armis.com/blueborne/ https://access.redhat.com/security/vulnerabilities/blueborne https://access.redhat.com/solutions/3177231 https://access.redhat.com/blogs/product-security/posts/blueborne

An upstream patch:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e860d2c904d1a9f38a24eb44c9f34b8f915a6ea3

Other sources

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

Launchpad

Affected Software

50 affected componentsFixes available
debian/linux<=4.12.12-2, <=3.12.9-1
3.16.43-2+deb8u44.9.30-2+deb9u44.12.13-1
Linux Linux kernel>=2.6.32<3.2.94
Linux Linux kernel>=3.3<3.16.49
Linux Linux kernel>=3.17<3.18.71
Linux Linux kernel>=3.19<4.1.45
Linux Linux kernel>=4.2<4.4.88
Linux Linux kernel>=4.5<4.9.50
Linux Linux kernel>=4.10<4.12.13
Linux Linux kernel>=4.13<4.13.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Nvidia Jetson Tk1=r21
Nvidia Jetson Tk1=r24
Nvidia Jetson TX1=r21
Nvidia Jetson TX1=r24
Linux Linux kernel
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=6.2
redhat Enterprise Linux Server Aus=6.4
redhat Enterprise Linux Server Aus=6.6
redhat Enterprise Linux Server Aus=7.2
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Eus=6.7
redhat Enterprise Linux Server Eus=7.2
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Eus=7.7
redhat Enterprise Linux Server Tus=6.5
redhat Enterprise Linux Server Tus=6.6
redhat Enterprise Linux Server Tus=7.2
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.4
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
All of the following
Any of the following
Nvidia Jetson Tk1=r21
Nvidia Jetson Tk1=r24
Nvidia Jetson TX1=r21
Nvidia Jetson TX1=r24
Linux Linux kernel
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Sep 8, 2017
Data Sourced
via Red Hat·08:13 AM
DescriptionSeverityAffected Software
Sep 12, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:23 PM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·01:33 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:40 AM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-1000251?

CVE-2017-1000251 is classified with a high severity due to its ability to result in a stack buffer overflow in the Linux kernel Bluetooth system.

2

How do I fix CVE-2017-1000251?

To fix CVE-2017-1000251, upgrade to the appropriate patched versions of the Linux kernel listed in the vulnerability details.

3

What systems are affected by CVE-2017-1000251?

CVE-2017-1000251 affects multiple versions of the Linux kernel and Debian GNU/Linux systems as well as certain NVIDIA Jetson devices.

4

Can attackers exploit CVE-2017-1000251 remotely?

Yes, attackers within Bluetooth transmission range can exploit CVE-2017-1000251 to execute arbitrary code.

5

Is there a known exploit for CVE-2017-1000251?

While specific exploit code for CVE-2017-1000251 may not be publicly available, the nature of the vulnerability allows for potential exploitation given the right conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203