Lucene search

K
redhatcveRedhat.comRH:CVE-2020-36386
HistoryJun 08, 2021 - 2:14 p.m.

CVE-2020-36386

2021-06-0814:14:23
redhat.com
access.redhat.com
28

0.001 Low

EPSS

Percentile

34.3%

A flaw out of bounds memory access in the Linux kernel bluetooth subsystem was found in the way when some data being read about the bluetooth device with the hci_extended_inquiry_result_evt call. A local user could use this flaw to crash the system or read some data out of memory bounds that can lead to data confidentiality threat.

Mitigation

To mitigate this issue, prevent the module bluetooth from being loaded (if Bluetooth not required for the system). Please see <https://access.redhat.com/solutions/41278&gt; for information on how to blacklist a kernel module to prevent it from loading automatically.