Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-2002

Опубликовано: 26 мая 2023
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed6.1.27-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2023/04/16/3

  • Fixed by: https://git.kernel.org/linus/25c150ac103a4ebeed0319994c742a90634ddf18

  • Fixed by: https://lore.kernel.org/linux-bluetooth/20230416081404.8227-1-lrh2000@pku.edu.cn/

  • Hardening: https://lore.kernel.org/linux-bluetooth/20230416080251.7717-1-lrh2000@pku.edu.cn/

EPSS

Процентиль: 57%
0.00359
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 2 лет назад

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.

CVSS3: 6.8
redhat
около 2 лет назад

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.

CVSS3: 6.8
nvd
около 2 лет назад

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.

CVSS3: 6.8
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 6.8
github
около 2 лет назад

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.

EPSS

Процентиль: 57%
0.00359
Низкий