CVE-2017-1000251

HIGH

Linux Kernel <4.14 - RCE

Title source: llm

Description

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

Exploits (10)

exploitdb WORKING POC
by Marcin Kozlowski · textdoslinux
https://www.exploit-db.com/exploits/42762
github WORKING POC 38 stars
by Miracle963 · pythonpoc
https://github.com/Miracle963/bluetooth-cve/tree/master/littl_tools/CVE-2017-1000251
nomisec WORKING POC 17 stars
by hayzamjs · poc
https://github.com/hayzamjs/Blueborne-CVE-2017-1000251
nomisec WORKING POC 6 stars
by sgxgsx · poc
https://github.com/sgxgsx/blueborne-CVE-2017-1000251
nomisec WORKING POC 5 stars
by own2pwn · poc
https://github.com/own2pwn/blueborne-CVE-2017-1000251-POC
gitlab NO CODE
by aseyor1 · poc
https://gitlab.com/aseyor1/blueborne-CVE-2017-1000251
gitlab NO CODE
by hhao020 · poc
https://gitlab.com/hhao020/blueborne-CVE-2017-1000251
gitlab WORKING POC
by neville133 · poc
https://gitlab.com/neville133/blueborne-CVE-2017-1000251
nomisec WORKING POC
by istanescu · poc
https://github.com/istanescu/CVE-2017-1000251_Exploit
nomisec WORKING POC
by tlatkdgus1 · poc
https://github.com/tlatkdgus1/blueborne-CVE-2017-1000251

References (21)

... and 1 more

Scores

CVSS v3 8.0
EPSS 0.0303
EPSS Percentile 86.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (35)
debian/debian_linux 8.0
debian/debian_linux 9.0
linux/linux_kernel 2.6.32 - 3.2.94
nvidia/jetson_tk1 r21
nvidia/jetson_tk1 r24
nvidia/jetson_tx1 r21
nvidia/jetson_tx1 r24
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 6.0
... and 25 more
Published Sep 12, 2017
Tracked Since Feb 18, 2026