USN-4591-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 19 Oct 2020, 23:51
Last modified:03 Jun 2026, 13:33

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Oct 2020, 23:51
Published
Vulnerability first disclosed
03 Jun 2026, 13:33
Last Modified
Vulnerability information updated

Description

linux, linux-hwe, linux-hwe-5.4, linux-oem, linux-raspi, linux-raspi-5.4, linux-snapdragon vulnerabilities Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux kernel contained a type-confusion error. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-12351) Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate remote attacker could use this to expose sensitive information (kernel memory). (CVE-2020-12352)

Affected Systems

  • ubuntulinux

    < 4.15.0-122.124 | < 5.4.0-52.57

  • ubuntulinux-hwe

    < 4.15.0-122.124~16.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-52.57~18.04.1

  • ubuntulinux-oem

    < 4.15.0-1100.110

  • ubuntulinux-raspi

    < 5.4.0-1022.25

  • ubuntulinux-raspi-5.4

    < 5.4.0-1022.25~18.04.1

  • ubuntulinux-snapdragon

    < 4.15.0-1090.99

References (3)