3.3
CVSSv2

CVE-2020-24490

Published: 02/02/2021 Updated: 21/07/2021
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Improper buffer restrictions in the BlueZ component of Linux prior to 5.10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bluez bluez -

Vendor Advisories

Synopsis Important: kernel-rt security update Type/Severity Security Advisory: Important Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base sc ...
Synopsis Important: kernel security update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, w ...
In binder_release_work of binderc, there is a possible use-after-free due to improper locking This could lead to local escalation of privilege in the kernel with no additional execution privileges needed User interaction is not needed for exploitationProduct: AndroidVersions: Android kernelAndroid ID: A-161151868References: N/A (<a href=http ...
In binder_release_work of binderc, there is a possible use-after-free due to improper locking This could lead to local escalation of privilege in the kernel with no additional execution privileges needed User interaction is not needed for exploitationProduct: AndroidVersions: Android kernelAndroid ID: A-161151868References: N/A (<a href=http ...
Improper buffer restrictions in the BlueZ component of Linux before 510 may allow an unauthenticated user to potentially enable denial of service via adjacent access ...

Github Repositories

proj283-Automated-Security-Testing-of-Protocol-Stacks-in-OS-kernels 标题 操作系统内核协议栈的自动化安全测试 Automated Security Testing of Protocol Stacks in OS kernels 项目描述 操作系统内核中集成了TCP/IP、WiFi、蓝牙、USB等多种主流协议栈,用于实现设备间的数据传输和通信交互。然而,现有内核协议栈的缺陷