CVE-2020-25662

medium

Description

A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.

References

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25662

https://access.redhat.com/security/vulnerabilities/BleedingTooth

https://access.redhat.com/security/cve/CVE-2020-12352

Details

Source: Mitre, NVD

Published: 2020-11-05

Updated: 2023-02-12

Risk Information

CVSS v2

Base Score: 3.3

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: Medium