kernel: Heap address information leak while using L2CAP_PARSE_CONF_RSP
Published Apr 11, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.83%
Description
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
Affected products
-
- Version before 5.1-rc1StatusaffectedConstraints-
- Version fixed in 5.1-rc1StatusaffectedConstraints-
- Version
Configuration 1
- ≤ 5.1
Configuration 2
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 3
- 8.0
Configuration 4
- 8.0
- 4.0
- 8.0
- 7.0
- 8.1
- 8.2
- 8.4
- 7
- 8
- 7
- 8
- 8.2
- 8.4
- 8.2
- 8.4
- 7.0
- 8.2
- 8.4
- 8.2
- 8.4
- 7.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.el7
Fixed · RHSA-2019:2029
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.18.1.el7a
Fixed · RHSA-2020:0740
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.rt56.1022.el7
Fixed · RHSA-2019:2043
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.rt24.93.el8
Fixed · RHSA-2019:3309
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise MRG 2
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.el7 | Fixed | RHSA-2019:2029 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.18.1.el7a | Fixed | RHSA-2020:0740 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.rt56.1022.el7 | Fixed | RHSA-2019:2043 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.rt24.93.el8 | Fixed | RHSA-2019:3309 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
- Disabling the bluetooth hardware in the bios. - Prevent loading of the bluetooth kernel modules. - Disable the bluetooth connection by putting the system in "airport" mode.
References (21)
- http://www.openwall.com/lists/oss-security/2019/06/27/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/27/7 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/08/12/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2029 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2043 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3309 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3517 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0740 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3460 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1663179 x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory
- https://git.kernel.org/linus/af3d5d1c87664a4f150fcf3534c6567cb19909b0 x_refsource_CONFIRMPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lore.kernel.org/linux-bluetooth/20190110062917.GB15047%40kroah.com/ mailing-listx_refsource_MLIST
- https://marc.info/?l=oss-security&m=154721580222522&w=2 mailing-listx_refsource_MLISTExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-3460
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3460.html x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3460
Change history (0)
No recorded changes yet.