CVE-2020-12351: Input Validation
A flaw was found in the way the Linux kernel Bluetooth implementation handled L2CAP packets with A2MP CID. A remote attacker in adjacent range could use this flaw to crash the system causing denial of service or potentially execute arbitrary code on the system by sending a specially crafted L2CAP packet.
Other sources
A flaw was found in the way the Linux kernel’s Bluetooth implementation handled L2CAP (Logical Link Control and Adaptation Protocol) packets with A2MP (Alternate MAC-PHY Manager Protocol) CID (Channel Identifier). This flaw allows a remote attacker in an adjacent range to crash the system, causing a denial of service or potentially executing arbitrary code on the system by sending a specially crafted L2CAP packet. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-12351.
What is the severity of CVE-2020-12351?
The severity of CVE-2020-12351 is high with a CVSS score of 8.8.
What is the impact of CVE-2020-12351?
CVE-2020-12351 allows a remote attacker to crash the system, potentially causing a denial of service.
How can I fix CVE-2020-12351?
To fix CVE-2020-12351, update the affected software to the recommended versions.
Where can I find more information about CVE-2020-12351?
You can find more information about CVE-2020-12351 on the Red Hat Bugzilla and Red Hat Security Advisories websites.