CVE-2017-15868: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: from 3.2, before 3.2.97 (fixed in 3.2.97); from 3.3, before 3.10.108 (fixed in 3.10.108); from 3.11, before 3.16.52 (fixed in 3.16.52); from 3.17, before 3.18.64 (fixed in 3.18.64)
Published 2017-12-05. Last modified 2026-06-17.