{"id":"LSN-0073-1","summary":"Kernel Live Patch Security Notice","details":"Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux\nkernel contained a type-confusion error. A physically proximate remote\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2020-12351)\n\nAndy Nguyen discovered that the Bluetooth A2MP implementation in the Linux\nkernel did not properly initialize memory in some situations. A physically\nproximate remote attacker could use this to expose sensitive information\n(kernel memory). (CVE-2020-12352)\n\nAndy Nguyen discovered that the Bluetooth HCI event packet parser in the\nLinux kernel did not properly handle event advertisements of certain sizes,\nleading to a heap-based buffer overflow. A physically proximate remote\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2020-24490)","modified":"2026-04-27T15:11:45.253756Z","published":"2020-10-23T07:23:57Z","upstream":["CVE-2020-12351","CVE-2020-12352","CVE-2020-24490","UBUNTU-CVE-2020-12351","UBUNTU-CVE-2020-12352","UBUNTU-CVE-2020-24490"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/LSN-0073-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-12351"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-12352"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-24490"}],"affected":[{"package":{"name":"linux-aws","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/linux-aws@4.15.0-1190.203?arch=source&distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.15.0-1001.1","4.15.0-1003.3","4.15.0-1005.5","4.15.0-1006.6","4.15.0-1007.7","4.15.0-1009.9","4.15.0-1010.10","4.15.0-1011.11","4.15.0-1016.16","4.15.0-1017.17","4.15.0-1019.19","4.15.0-1020.20","4.15.0-1021.21","4.15.0-1023.23","4.15.0-1025.25","4.15.0-1027.27","4.15.0-1029.30","4.15.0-1031.33","4.15.0-1032.34","4.15.0-1033.35","4.15.0-1034.36","4.15.0-1035.37","4.15.0-1037.39","4.15.0-1039.41","4.15.0-1040.42","4.15.0-1041.43","4.15.0-1043.45","4.15.0-1044.46","4.15.0-1045.47","4.15.0-1047.49","4.15.0-1048.50","4.15.0-1050.52","4.15.0-1051.53","4.15.0-1052.54","4.15.0-1054.56","4.15.0-1056.58","4.15.0-1057.59","4.15.0-1058.60","4.15.0-1060.62","4.15.0-1063.67","4.15.0-1065.69","4.15.0-1066.70","4.15.0-1067.71","4.15.0-1073.77","4.15.0-1076.80","4.15.0-1077.81","4.15.0-1079.83","4.15.0-1080.84","4.15.0-1082.86","4.15.0-1083.87","4.15.0-1086.91","4.15.0-1087.92","4.15.0-1088.93","4.15.0-1090.95","4.15.0-1091.96","4.15.0-1092.98","4.15.0-1093.99","4.15.0-1094.101","4.15.0-1095.102","4.15.0-1096.103","4.15.0-1097.104","4.15.0-1098.105","4.15.0-1099.106","4.15.0-1101.108","4.15.0-1102.109","4.15.0-1103.110","4.15.0-1106.113","4.15.0-1109.116","4.15.0-1110.117","4.15.0-1111.118","4.15.0-1112.119","4.15.0-1114.121","4.15.0-1115.122","4.15.0-1116.123","4.15.0-1118.125","4.15.0-1119.127","4.15.0-1121.129","4.15.0-1123.132","4.15.0-1124.133","4.15.0-1126.135","4.15.0-1127.136","4.15.0-1128.137","4.15.0-1130.139","4.15.0-1133.143","4.15.0-1136.147","4.15.0-1137.148","4.15.0-1139.150","4.15.0-1140.151","4.15.0-1141.152","4.15.0-1142.154","4.15.0-1143.155","4.15.0-1144.156","4.15.0-1146.158","4.15.0-1147.159","4.15.0-1148.160","4.15.0-1150.163","4.15.0-1151.164","4.15.0-1153.166","4.15.0-1154.167","4.15.0-1155.168","4.15.0-1156.169","4.15.0-1157.170","4.15.0-1158.171","4.15.0-1159.172","4.15.0-1160.173","4.15.0-1161.174","4.15.0-1162.175","4.15.0-1163.176","4.15.0-1164.177","4.15.0-1165.178","4.15.0-1166.179","4.15.0-1167.180","4.15.0-1168.181","4.15.0-1169.182","4.15.0-1170.183","4.15.0-1172.185","4.15.0-1173.186","4.15.0-1174.187","4.15.0-1175.188","4.15.0-1176.189","4.15.0-1177.190","4.15.0-1178.191","4.15.0-1179.192","4.15.0-1180.193","4.15.0-1181.194","4.15.0-1182.195","4.15.0-1183.196","4.15.0-1184.197","4.15.0-1185.198","4.15.0-1186.199","4.15.0-1187.200","4.15.0-1188.201","4.15.0-1189.202","4.15.0-1190.203"],"ecosystem_specific":{"module_version":"73","module_name_regex":"lkp_Ubuntu_4_15_0[_|\\d]+_aws_(\\d+)","availability":"Livepatch subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/lsn/LSN-0073-1.json"}},{"package":{"name":"linux","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/linux@4.15.0-122.124?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.0-122.124"}]}],"versions":["4.13.0-16.19","4.13.0-17.20","4.13.0-25.29","4.13.0-32.35","4.15.0-10.11","4.15.0-12.13","4.15.0-13.14","4.15.0-15.16","4.15.0-19.20","4.15.0-20.21","4.15.0-22.24","4.15.0-23.25","4.15.0-24.26","4.15.0-29.31","4.15.0-30.32","4.15.0-32.35","4.15.0-33.36","4.15.0-34.37","4.15.0-36.39","4.15.0-38.41","4.15.0-39.42","4.15.0-42.45","4.15.0-43.46","4.15.0-44.47","4.15.0-45.48","4.15.0-46.49","4.15.0-47.50","4.15.0-48.51","4.15.0-50.54","4.15.0-51.55","4.15.0-52.56","4.15.0-54.58","4.15.0-55.60","4.15.0-58.64","4.15.0-60.67","4.15.0-62.69","4.15.0-64.73","4.15.0-65.74","4.15.0-66.75","4.15.0-69.78","4.15.0-70.79","4.15.0-72.81","4.15.0-74.84","4.15.0-76.86","4.15.0-88.88","4.15.0-91.92","4.15.0-96.97","4.15.0-99.100","4.15.0-101.102","4.15.0-106.107","4.15.0-108.109","4.15.0-109.110","4.15.0-111.112","4.15.0-112.113","4.15.0-115.116","4.15.0-117.118","4.15.0-118.119","4.15.0-121.123"],"ecosystem_specific":{"module_version":"73","module_name_regex":"lkp_Ubuntu_4_15_0[_|\\d]+_(?:generic|lowlatency)_(\\d+)","availability":"Livepatch subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/lsn/LSN-0073-1.json"}},{"package":{"name":"linux-oem","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/linux-oem@4.15.0-1100.110?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.0-1100.110"}]}],"versions":["4.15.0-1002.3","4.15.0-1004.5","4.15.0-1006.9","4.15.0-1008.11","4.15.0-1009.12","4.15.0-1012.15","4.15.0-1013.16","4.15.0-1015.18","4.15.0-1017.20","4.15.0-1018.21","4.15.0-1021.24","4.15.0-1024.29","4.15.0-1026.31","4.15.0-1028.33","4.15.0-1030.35","4.15.0-1033.38","4.15.0-1034.39","4.15.0-1035.40","4.15.0-1036.41","4.15.0-1038.43","4.15.0-1039.44","4.15.0-1043.48","4.15.0-1045.50","4.15.0-1050.57","4.15.0-1056.65","4.15.0-1057.66","4.15.0-1059.68","4.15.0-1063.72","4.15.0-1064.73","4.15.0-1065.75","4.15.0-1066.76","4.15.0-1067.77","4.15.0-1069.79","4.15.0-1073.83","4.15.0-1076.86","4.15.0-1079.89","4.15.0-1080.90","4.15.0-1081.91","4.15.0-1087.97","4.15.0-1090.100","4.15.0-1091.101","4.15.0-1093.103","4.15.0-1094.104","4.15.0-1096.106","4.15.0-1097.107","4.15.0-1099.109"],"ecosystem_specific":{"module_version":"73","module_name_regex":"lkp_Ubuntu_4_15_0[_|\\d]+_oem_(\\d+)","availability":"Livepatch subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/lsn/LSN-0073-1.json"}},{"package":{"name":"linux-aws","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/linux-aws@5.4.0-1157.167?arch=source&distro=esm-infra/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.0-1003.3","5.3.0-1008.9","5.3.0-1009.10","5.3.0-1010.11","5.4.0-1005.5","5.4.0-1007.7","5.4.0-1008.8","5.4.0-1009.9","5.4.0-1011.11","5.4.0-1015.15","5.4.0-1017.17","5.4.0-1018.18","5.4.0-1020.20","5.4.0-1021.21","5.4.0-1022.22","5.4.0-1024.24","5.4.0-1025.25","5.4.0-1028.29","5.4.0-1029.30","5.4.0-1030.31","5.4.0-1032.33","5.4.0-1034.35","5.4.0-1035.37","5.4.0-1037.39","5.4.0-1038.40","5.4.0-1039.41","5.4.0-1041.43","5.4.0-1043.45","5.4.0-1045.47","5.4.0-1047.49","5.4.0-1048.50","5.4.0-1049.51","5.4.0-1051.53","5.4.0-1054.57","5.4.0-1055.58","5.4.0-1056.59","5.4.0-1057.60","5.4.0-1058.61","5.4.0-1059.62","5.4.0-1060.63","5.4.0-1061.64","5.4.0-1063.66","5.4.0-1064.67","5.4.0-1065.68","5.4.0-1066.69","5.4.0-1068.72","5.4.0-1069.73","5.4.0-1071.76","5.4.0-1072.77","5.4.0-1073.78","5.4.0-1075.80","5.4.0-1078.84","5.4.0-1080.87","5.4.0-1081.88","5.4.0-1083.90","5.4.0-1084.91","5.4.0-1085.92","5.4.0-1086.93","5.4.0-1088.96","5.4.0-1089.97","5.4.0-1092.100","5.4.0-1093.101","5.4.0-1094.102","5.4.0-1096.104","5.4.0-1097.105","5.4.0-1099.107","5.4.0-1100.108","5.4.0-1101.109","5.4.0-1102.110","5.4.0-1103.111","5.4.0-1104.112","5.4.0-1105.113","5.4.0-1106.114","5.4.0-1107.115","5.4.0-1108.116","5.4.0-1109.118","5.4.0-1110.119","5.4.0-1111.120","5.4.0-1112.121","5.4.0-1113.123","5.4.0-1114.124","5.4.0-1116.126","5.4.0-1117.127","5.4.0-1118.128","5.4.0-1119.129","5.4.0-1120.130","5.4.0-1121.131","5.4.0-1122.132","5.4.0-1123.133","5.4.0-1124.134","5.4.0-1125.135","5.4.0-1126.136","5.4.0-1127.137","5.4.0-1128.138","5.4.0-1129.139","5.4.0-1130.140","5.4.0-1131.141","5.4.0-1132.142","5.4.0-1133.143","5.4.0-1134.144","5.4.0-1135.145","5.4.0-1136.146","5.4.0-1137.147","5.4.0-1139.149","5.4.0-1140.150","5.4.0-1142.152","5.4.0-1144.154","5.4.0-1145.155","5.4.0-1146.156","5.4.0-1147.157","5.4.0-1148.158","5.4.0-1149.159","5.4.0-1150.160","5.4.0-1151.161","5.4.0-1152.162","5.4.0-1153.163","5.4.0-1154.164","5.4.0-1156.166","5.4.0-1157.167"],"ecosystem_specific":{"module_version":"73","module_name_regex":"lkp_Ubuntu_5_4_0[_|\\d]+_aws_(\\d+)","availability":"Livepatch subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/lsn/LSN-0073-1.json"}},{"package":{"name":"linux-azure","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/linux-azure@5.4.0-1161.167?arch=source&distro=esm-infra/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.0-1003.3","5.3.0-1008.9","5.3.0-1009.10","5.4.0-1006.6","5.4.0-1008.8","5.4.0-1009.9","5.4.0-1010.10","5.4.0-1012.12","5.4.0-1016.16","5.4.0-1019.19","5.4.0-1020.20","5.4.0-1022.22","5.4.0-1023.23","5.4.0-1025.25","5.4.0-1026.26","5.4.0-1031.32","5.4.0-1032.33","5.4.0-1034.35","5.4.0-1035.36","5.4.0-1036.38","5.4.0-1039.41","5.4.0-1040.42","5.4.0-1041.43","5.4.0-1043.45","5.4.0-1044.46","5.4.0-1046.48","5.4.0-1047.49","5.4.0-1048.50","5.4.0-1049.51","5.4.0-1051.53","5.4.0-1055.57","5.4.0-1056.58","5.4.0-1058.60","5.4.0-1059.62","5.4.0-1061.64","5.4.0-1062.65","5.4.0-1063.66","5.4.0-1064.67","5.4.0-1065.68","5.4.0-1067.70","5.4.0-1068.71","5.4.0-1069.72","5.4.0-1070.73","5.4.0-1072.75","5.4.0-1073.76","5.4.0-1074.77","5.4.0-1077.80","5.4.0-1078.81","5.4.0-1080.83","5.4.0-1083.87","5.4.0-1085.90","5.4.0-1086.91","5.4.0-1089.94","5.4.0-1090.95","5.4.0-1091.96","5.4.0-1094.100","5.4.0-1095.101","5.4.0-1098.104","5.4.0-1100.106","5.4.0-1101.107","5.4.0-1103.109","5.4.0-1104.110","5.4.0-1105.111","5.4.0-1106.112","5.4.0-1107.113","5.4.0-1108.114","5.4.0-1109.115","5.4.0-1110.116","5.4.0-1111.117","5.4.0-1112.118","5.4.0-1113.119","5.4.0-1114.120","5.4.0-1115.122","5.4.0-1116.123","5.4.0-1117.124","5.4.0-1118.125","5.4.0-1119.126","5.4.0-1120.127","5.4.0-1121.128","5.4.0-1122.129","5.4.0-1123.130","5.4.0-1124.131","5.4.0-1126.133","5.4.0-1127.134","5.4.0-1128.135","5.4.0-1129.136","5.4.0-1130.137","5.4.0-1131.138","5.4.0-1132.139","5.4.0-1133.140","5.4.0-1134.141","5.4.0-1135.142","5.4.0-1136.143","5.4.0-1137.144","5.4.0-1138.145","5.4.0-1139.146","5.4.0-1140.147","5.4.0-1142.149","5.4.0-1143.150","5.4.0-1145.152","5.4.0-1147.154","5.4.0-1148.155","5.4.0-1149.156","5.4.0-1150.157","5.4.0-1151.158","5.4.0-1152.159","5.4.0-1153.160","5.4.0-1154.161","5.4.0-1156.163","5.4.0-1157.164","5.4.0-1160.166","5.4.0-1161.167"],"ecosystem_specific":{"module_version":"73","module_name_regex":"lkp_Ubuntu_5_4_0[_|\\d]+_azure_(\\d+)","availability":"Livepatch subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/lsn/LSN-0073-1.json"}},{"package":{"name":"linux-gcp","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/linux-gcp@5.4.0-1160.169?arch=source&distro=esm-infra/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.0-1004.4","5.3.0-1009.10","5.3.0-1011.12","5.4.0-1005.5","5.4.0-1007.7","5.4.0-1008.8","5.4.0-1009.9","5.4.0-1011.11","5.4.0-1015.15","5.4.0-1018.18","5.4.0-1019.19","5.4.0-1021.21","5.4.0-1022.22","5.4.0-1024.24","5.4.0-1025.25","5.4.0-1028.29","5.4.0-1029.31","5.4.0-1030.32","5.4.0-1032.34","5.4.0-1033.35","5.4.0-1034.37","5.4.0-1036.39","5.4.0-1037.40","5.4.0-1038.41","5.4.0-1040.43","5.4.0-1041.44","5.4.0-1042.45","5.4.0-1043.46","5.4.0-1044.47","5.4.0-1046.49","5.4.0-1049.53","5.4.0-1051.55","5.4.0-1052.56","5.4.0-1053.57","5.4.0-1055.59","5.4.0-1056.60","5.4.0-1057.61","5.4.0-1058.62","5.4.0-1059.63","5.4.0-1060.64","5.4.0-1062.66","5.4.0-1063.67","5.4.0-1064.68","5.4.0-1065.69","5.4.0-1067.71","5.4.0-1068.72","5.4.0-1069.73","5.4.0-1072.77","5.4.0-1073.78","5.4.0-1075.80","5.4.0-1078.84","5.4.0-1080.87","5.4.0-1083.91","5.4.0-1084.92","5.4.0-1086.94","5.4.0-1087.95","5.4.0-1089.97","5.4.0-1090.98","5.4.0-1092.101","5.4.0-1093.102","5.4.0-1096.105","5.4.0-1097.106","5.4.0-1098.107","5.4.0-1100.109","5.4.0-1101.110","5.4.0-1102.111","5.4.0-1103.112","5.4.0-1104.113","5.4.0-1105.114","5.4.0-1106.115","5.4.0-1107.116","5.4.0-1108.117","5.4.0-1109.118","5.4.0-1110.119","5.4.0-1111.120","5.4.0-1112.121","5.4.0-1113.122","5.4.0-1115.124","5.4.0-1116.125","5.4.0-1117.126","5.4.0-1118.127","5.4.0-1120.129","5.4.0-1121.130","5.4.0-1122.131","5.4.0-1123.132","5.4.0-1124.133","5.4.0-1125.134","5.4.0-1126.135","5.4.0-1127.136","5.4.0-1128.137","5.4.0-1129.138","5.4.0-1130.139","5.4.0-1131.140","5.4.0-1132.141","5.4.0-1133.142","5.4.0-1134.143","5.4.0-1135.144","5.4.0-1136.145","5.4.0-1137.146","5.4.0-1138.147","5.4.0-1139.148","5.4.0-1140.149","5.4.0-1141.150","5.4.0-1142.151","5.4.0-1143.152","5.4.0-1145.154","5.4.0-1146.155","5.4.0-1147.156","5.4.0-1148.157","5.4.0-1149.158","5.4.0-1150.159","5.4.0-1151.160","5.4.0-1152.161","5.4.0-1153.162","5.4.0-1154.163","5.4.0-1155.164","5.4.0-1156.165","5.4.0-1157.166","5.4.0-1159.168","5.4.0-1160.169"],"ecosystem_specific":{"module_version":"73","module_name_regex":"lkp_Ubuntu_5_4_0[_|\\d]+_gcp_(\\d+)","availability":"Livepatch subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/lsn/LSN-0073-1.json"}},{"package":{"name":"linux","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/linux@5.4.0-52.57?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.0-52.57"}]}],"versions":["5.3.0-18.19","5.3.0-24.26","5.4.0-9.12","5.4.0-18.22","5.4.0-21.25","5.4.0-24.28","5.4.0-25.29","5.4.0-26.30","5.4.0-28.32","5.4.0-29.33","5.4.0-31.35","5.4.0-33.37","5.4.0-37.41","5.4.0-39.43","5.4.0-40.44","5.4.0-42.46","5.4.0-45.49","5.4.0-47.51","5.4.0-48.52","5.4.0-51.56"],"ecosystem_specific":{"module_version":"73","module_name_regex":"lkp_Ubuntu_5_4_0[_|\\d]+_(?:generic|lowlatency)_(\\d+)","availability":"Livepatch subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/lsn/LSN-0073-1.json"}}],"schema_version":"1.7.5"}