[manjaro-security] [arch-security] [ASA-201709-8] linux-lts: arbitrary code execution
anthraxx at archlinux.org
Thu Sep 14 17:43:29 CEST 2017
Arch Linux Security Advisory ASA-201709-8
Date : 2017-09-14
CVE-ID : CVE-2017-1000251
Package : linux-lts
Type : arbitrary code execution
Remote : Yes
Link : https://security.archlinux.org/AVG-393
The package linux-lts before version 4.9.49-2 is vulnerable to
arbitrary code execution.
Upgrade to 4.9.49-2.
# pacman -Syu "linux-lts>=4.9.49-2"
The problem has been fixed upstream but no release is available yet.
A stack buffer overflow flaw was found in the way the Bluetooth
subsystem of the Linux kernel processed pending L2CAP configuration
responses from a client. On systems with the stack protection feature
enabled in the kernel (CONFIG_CC_STACKPROTECTOR=y, which is enabled on
all architectures), an unauthenticated attacker able to initiate a
connection to a system via Bluetooth could use this flaw to crash the
system. Due to the nature of the stack protection feature, code
execution cannot be fully ruled out, although it is unlikely. On
systems without the stack protection feature, an unauthenticated
attacker able to initiate a connection to a system via Bluetooth could
use this flaw to remotely execute arbitrary code on the system with
ring 0 (kernel) privileges.
An unauthenticated attacker able to initiate a connection via Bluetooth
is able to crash the system or possibly execute arbitrary code.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 866 bytes
Desc: OpenPGP digital signature
More information about the manjaro-security