CVE-2018-9419

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 19, 2024
Updated: Nov 22, 2024
CWE ID 125
CWE ID 787

Summary

CVE-2018-9419 is a vulnerability affecting the l2c_ble.cc file in the Linux Bluetooth subsystem. The issue lies in the function 'l2cble_process_sig_cmd' where a bounds check is missing, leading to a possible out-of-bounds read. This flaw can result in remote information disclosure, allowing attackers to access sensitive data without requiring any additional execution privileges. User interaction is not necessary for exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share