CVE-2017-15868: Input Validation
Last updated 24 July 2024
Other sources
The bnepaddconnection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-15868.
What is the title of the vulnerability?
The title of the vulnerability is 'The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.'
What is the description of the vulnerability?
The vulnerability allows local users to gain privileges via a crafted application by exploiting the bnep_add_connection function in the Linux kernel before version 3.19.
What software versions are affected?
The affected software versions are Linux kernel versions before 3.19.
Are there any references for this vulnerability?
Yes, you can find references for this vulnerability at the following links: [Reference 1](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=71bb99a02b32b4cc4265118e85f6035ca72923f0), [Reference 2](https://github.com/torvalds/linux/commit/71bb99a02b32b4cc4265118e85f6035ca72923f0), [Reference 3](https://patchwork.kernel.org/patch/9882449/)