Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-25661
HistoryNov 05, 2020 - 12:00 a.m.

CVE-2020-25661

2020-11-0500:00:00
ubuntu.com
ubuntu.com
36
red hat
cve-2020-12351
regression
linux kernel
bluetooth
remote code execution

CVSS2

8.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.6%

A Red Hat only CVE-2020-12351 regression issue was found in the way the
Linux kernel’s Bluetooth implementation handled L2CAP packets with A2MP
CID. This flaw allows a remote attacker in an adjacent range to crash the
system, causing a denial of service or potentially executing arbitrary code
on the system by sending a specially crafted L2CAP packet. The highest
threat from this vulnerability is to confidentiality, integrity, as well as
system availability.

CVSS2

8.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.6%