Lucene search

K
redhatcveRedhat.comRH:CVE-2019-11884
HistoryApr 08, 2020 - 5:29 a.m.

CVE-2019-11884

2020-04-0805:29:15
redhat.com
access.redhat.com
35

0.0004 Low

EPSS

Percentile

10.1%

A flaw was found in the Linux kernel’s implementation of the Bluetooth Human Interface Device Protocol (HIDP). A local attacker with access permissions to the Bluetooth device can issue an IOCTL which will trigger the do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c.c. This function can leak potentially sensitive information from the kernel stack memory via a HIDPCONNADD command because a name field may not be correctly NULL terminated.