CVE-2017-1000251
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 16%
from disclosure to weapon9 days
Published on NVDSep 12
1st PoC+9d
exploitation probability
16%top 3% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
Affected products
n/a · n/apublic PoCs found — 7
githubgithub.com/hayzamjs/Blueborne-CVE-2017-1000251★ 18githubgithub.com/sgxgsx/blueborne-CVE-2017-1000251★ 6githubgithub.com/own2pwn/blueborne-CVE-2017-1000251-POC★ 5githubgithub.com/istanescu/CVE-2017-1000251_Exploit★ 0githubgithub.com/tlatkdgus1/blueborne-CVE-2017-1000251★ 0cve_referencewww.exploit-db.com/exploits/42762/unverifiedexploitdbwww.exploit-db.com/exploits/42762unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://nvidia.custhelp.com/app/answers/detail/a_id/4561https://access.redhat.com/errata/RHSA-2017:2679https://access.redhat.com/errata/RHSA-2017:2680https://access.redhat.com/errata/RHSA-2017:2681https://access.redhat.com/errata/RHSA-2017:2682https://access.redhat.com/errata/RHSA-2017:2683https://access.redhat.com/errata/RHSA-2017:2704https://access.redhat.com/errata/RHSA-2017:2705https://access.redhat.com/errata/RHSA-2017:2706https://access.redhat.com/errata/RHSA-2017:2707https://access.redhat.com/errata/RHSA-2017:2731https://access.redhat.com/errata/RHSA-2017:2732