Out-of-bounds write in Linux kernel - CVE-2017-13220

 

Out-of-bounds write in Linux kernel - CVE-2017-13220

Published: May 2, 2018


Vulnerability identifier: #VU12340
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13220
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists in the Upstream kernel bluez due to put-of-bounds access. A local attacker can trigger memory corruption and gain root privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Linux kernel
Debian Linux
SUSE Linux

How to mitigate CVE-2017-13220

Install update from vendor's website.


External References

Related Security Bulletins