CVE-2020-12352: Input Validation
An information leak flaw was found in the way Linux kernel Bluetooth stack implementation handled initialization of stack memory when handling certain AMP packets. A remote attacker in adjacent range could use this flaw to leak small portions of stack memory on the system by sending a specially crafted AMP packets.
Other sources
An information leak flaw was found in the way Linux kernel’s Bluetooth stack implementation handled initialization of stack memory when handling certain AMP (Alternate MAC-PHY Manager Protocol) packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-12352?
CVE-2020-12352 is rated as a medium severity vulnerability due to its ability to leak information from stack memory.
How do I fix CVE-2020-12352?
To fix CVE-2020-12352, update to the appropriate kernel versions listed in your distribution's security advisory.
Which versions of the Linux kernel are affected by CVE-2020-12352?
CVE-2020-12352 affects multiple versions of the Linux kernel including certain 3.10, 4.14, and 5.x versions.
Can CVE-2020-12352 be exploited remotely?
Yes, CVE-2020-12352 can be exploited by a remote attacker within adjacent range to leak memory.
What types of systems are vulnerable to CVE-2020-12352?
Systems running affected versions of the Linux kernel that utilize Bluetooth functionality are vulnerable to CVE-2020-12352.