CVE-2019-3459: Infoleak
A flaw was found in the Linux kernel's implementation of Logical Link Control and Adaptation Protocol (L2CAP), part of the Bluetooth stack. An attacker, within the range of standard Bluetooth transmissions, can create and send a specially crafted packet. The response to this specially crafted packet can contain part of the kernel stack which can be used in a further attack.
Other sources
A flaw was found in the Linux kernels implementation of Logical link control and adaptation protocol (L2CAP), part of the bluetooth stack.
An attacker with physical access within the range of standard bluetooth transmission can create a specially crafted packet. The response to this specially crafted packet can contain part of the kernel stack which can be used in a further attack.
Upstream patch: https://lore.kernel.org/linux-bluetooth/20190110062833.GA15047@kroah.com/
Oss-security post: https://seclists.org/oss-sec/2019/q1/58
Mitigation:
- Disabling the bluetooth hardware in the bios. - Prevent loading of the bluetooth kernel modules. - Disable the bluetooth connection by putting the system in "airport" mode.
— Red Hat
A heap address information leak while using L2CAPGETCONFOPT was discovered in the Linux kernel before 5.1-rc1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.rt56.1022.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.18.1.el7a - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.rt24.93.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Configuration
Prevent loading of the Bluetooth kernel modules so the Bluetooth stack cannot be used (e.g., ensure Bluetooth-related kernel modules are not loaded).
Linux kernel Bluetooth stack Prevent loading of Bluetooth kernel modules = disabled - Compensating control
Disable Bluetooth connectivity by putting the system in "airport" mode.
- Compensating control
Disable the Bluetooth hardware in the BIOS/firmware.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-3459?
CVE-2019-3459 has been rated as a moderate severity vulnerability.
How do I fix CVE-2019-3459?
To fix CVE-2019-3459, ensure your system is updated to a version of the Linux kernel that is not affected, such as those specified in the advisory.
What systems are affected by CVE-2019-3459?
CVE-2019-3459 impacts several versions of the Linux kernel on various systems including Red Hat, Ubuntu, and Debian.
Can CVE-2019-3459 be exploited remotely?
CVE-2019-3459 can be exploited by attackers within range of standard Bluetooth transmissions.
Is there a patch available for CVE-2019-3459?
Yes, patches for CVE-2019-3459 are available in the updated kernel releases from the affected distributions.