CVE-2017-13220
Published: 12 January 2018
An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.
From the Ubuntu Security Team
It was discovered that the Bluetooth HIP Protocol implementation in the Linux kernel did not properly validate HID connection setup information. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
Priority
Status
Package | Release | Status |
---|---|---|
bluez Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(kernel vuln)
|
xenial |
Not vulnerable
(kernel vuln)
|
|
bionic |
Not vulnerable
(kernel vuln)
|
|
upstream |
Not vulnerable
(kernel vuln)
|
|
trusty |
Does not exist
(trusty was not-affected [kernel vuln])
|
|
linux Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(4.10.0-19.21)
|
trusty |
Released
(3.13.0-149.199)
|
|
xenial |
Not vulnerable
(4.2.0-16.19)
|
|
bionic |
Not vulnerable
(4.13.0-16.19)
|
|
upstream |
Released
(3.19~rc3)
|
|
Patches: Introduced by b4f34d8d9d26b2428fa7cf7c8f97690a297978e6 |
||
linux-aws Launchpad, Ubuntu, Debian |
trusty |
Not vulnerable
(4.4.0-1002.2)
|
xenial |
Not vulnerable
(4.4.0-1001.10)
|
|
bionic |
Not vulnerable
(4.15.0-1001.1)
|
|
upstream |
Released
(3.19~rc3)
|
|
artful |
Does not exist
|
|
linux-azure Launchpad, Ubuntu, Debian |
trusty |
Not vulnerable
(4.15.0-1023.24~14.04.1)
|
xenial |
Not vulnerable
(4.11.0-1009.9)
|
|
upstream |
Released
(3.19~rc3)
|
|
bionic |
Not vulnerable
(4.15.0-1002.2)
|
|
artful |
Does not exist
|
|
linux-euclid Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.4.0-9019.20)
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-flo Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [abandoned])
|
|
xenial |
Ignored
(abandoned)
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-gcp Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.10.0-1004.4)
|
|
bionic |
Not vulnerable
(4.15.0-1001.1)
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-gke Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Ignored
(end of standard support, was needs-triage)
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-goldfish Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [abandoned])
|
|
xenial |
Ignored
(end of life, was needs-triage)
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-grouper Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [abandoned])
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-hwe Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.8.0-36.36~16.04.1)
|
|
bionic |
Not vulnerable
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.8.0-36.36~16.04.1)
|
|
bionic |
Released
(4.18.0-8.9~18.04.1)
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-kvm Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.4.0-1004.9)
|
|
bionic |
Not vulnerable
(4.15.0-1002.2)
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-lts-trusty Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-lts-utopic Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [end of standard support])
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-lts-vivid Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [end of standard support])
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-lts-wily Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [end of standard support])
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Not vulnerable
(4.4.0-13.29~14.04.1)
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-maguro Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [abandoned])
|
|
xenial |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
bionic |
Does not exist
|
|
linux-mako Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [abandoned])
|
|
xenial |
Ignored
(abandoned)
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-manta Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
(trusty was ignored [abandoned])
|
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-oem Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.13.0-1008.9)
|
|
bionic |
Not vulnerable
(4.15.0-1002.3)
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-raspi2 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(4.10.0-1004.6)
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.2.0-1013.19)
|
|
bionic |
Not vulnerable
(4.13.0-1005.5)
|
|
upstream |
Released
(3.19~rc3)
|
|
linux-snapdragon Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(4.4.0-1050.54)
|
trusty |
Does not exist
|
|
xenial |
Not vulnerable
(4.4.0-1012.12)
|
|
bionic |
Not vulnerable
|
|
upstream |
Released
(3.19~rc3)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |