CVE-2017-1000251 is a stack overflow vulnerability within the native Bluetooth stack (BlueZ) of the Linux Kernel, affecting versions 2.6.32 through 4.13.1, including distributions like Debian, Linux, NVIDIA, and Red Hat. This flaw allows for remote code execution in kernel space through specially crafted L2CAP configuration responses. With a CVSS score of 8.0 (HIGH), it represents a significant risk due to its network-adjacent attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a proof-of-concept exploit (EDB-42762) is publicly available, and the vulnerability has garnered substantial community discussion and media coverage, particularly in relation to the "BlueBorne" attack vector impacting billions of Bluetooth-enabled devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.32, < 3.2.94CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.16.49CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 3.18.71CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.19, < 4.1.45CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.2, < 4.4.88CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.