PT-2011-1008 · Linux+2 · Linux Kernel+2

CVE-2011-2492

·

Published

2011-07-15

·

Updated

2023-02-13

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.0-rc4
Description The bluetooth subsystem in the Linux kernel does not properly initialize certain data structures, allowing local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call. This issue is related to the l2cap sock getsockopt old function in net/bluetooth/l2cap sock.c and the rfcomm sock getsockopt old function in net/bluetooth/rfcomm/sock.c.
Recommendations For Linux kernel versions prior to 3.0-rc4, consider updating to version 3.0-rc4 or later to resolve the issue. As a temporary workaround, consider restricting access to the bluetooth subsystem to minimize the risk of exploitation.

Fix

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00069
CVE-2011-2492
DSA-2303-1
DSA-2310-1
RHSA-2011:0927
RHSA-2011:1189
RHSA-2011:1253
RHSA-2011_0927
RHSA-2011_1189
SUSE-SU-2014_0536-1
USN-1189-1
USN-1201-1
USN-1202-1
USN-1203-1
USN-1204-1
USN-1205-1
USN-1208-1
USN-1211-1
USN-1212-1
USN-1216-1
USN-1218-1
USN-1256-1

Affected Products

Linux Kernel
Red Hat
Suse