Early Access — Mondoo Vulnerability Intelligence is currently in preview.
Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux kernel contained a type-confusion error. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-12351)
Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate remote attacker could use this to expose sensitive information (kernel memory). (CVE-2020-12352)
4.15.0-122.124~16.04.14.15.0-122.1245.4.0-52.57~18.04.14.15.0-1100.1105.4.0-1022.25~18.04.14.15.0-1090.995.4.0-52.575.4.0-1022.25