vulnerability

Amazon Linux AMI: CVE-2017-1000251: Security patch for kernel (ALAS-2017-914)

Severity
8
CVSS
(AV:A/AC:L/Au:S/C:C/I:C/A:C)
Published
Sep 12, 2017
Added
Oct 27, 2017
Modified
Oct 14, 2022

Description

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

Solution

amazon-linux-upgrade-kernel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.