CVE-2020-25662
Summary
| CVE | CVE-2020-25662 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-05 21:15:00 UTC |
| Updated | 2023-02-12 23:40:00 UTC |
| Description | A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality. |
Risk And Classification
Problem Types: CWE-284 | CWE-665
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 8.3 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1891484 – (CVE-2020-25662) CVE-2020-25662 kernel: Red Hat only CVE-2020-12352 regression | CONFIRM | bugzilla.redhat.com | Issue Tracking, Mitigation, Vendor Advisory |
| 1891484 – (CVE-2020-25662) CVE-2020-25662 kernel: Red Hat only CVE-2020-12352 regression | MISC | bugzilla.redhat.com | |
| BleedingTooth - Kernel Bluetooth vulnerabilities - CVE-2020-12351, CVE-2020-12352, and CVE-2020-24490 - Red Hat Customer Portal | CONFIRM | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| Red Hat Customer Portal | CONFIRM | access.redhat.com | Mitigation, Vendor Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.