Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size value within the command header of a Logical Link Control and Adaptation Protocol (L2CAP) configuration request, leading to a buffer overflow.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Linux_kernel | Linux | * | 3.0 (excluding) | 
| Red Hat Enterprise Linux 6 | RedHat | kernel-0:2.6.32-131.12.1.el6 | * | 
| Red Hat Enterprise MRG 2 | RedHat | kernel-rt-0:2.6.33.9-rt31.75.el6rt | * | 
| Linux | Ubuntu | hardy | * | 
| Linux | Ubuntu | lucid | * | 
| Linux | Ubuntu | maverick | * | 
| Linux | Ubuntu | natty | * | 
| Linux | Ubuntu | upstream | * | 
| Linux-ec2 | Ubuntu | lucid | * | 
| Linux-ec2 | Ubuntu | maverick | * | 
| Linux-ec2 | Ubuntu | upstream | * | 
| Linux-flo | Ubuntu | upstream | * | 
| Linux-fsl-imx51 | Ubuntu | lucid | * | 
| Linux-fsl-imx51 | Ubuntu | upstream | * | 
| Linux-goldfish | Ubuntu | saucy | * | 
| Linux-goldfish | Ubuntu | upstream | * | 
| Linux-grouper | Ubuntu | saucy | * | 
| Linux-grouper | Ubuntu | upstream | * | 
| Linux-lts-backport-maverick | Ubuntu | lucid | * | 
| Linux-lts-backport-maverick | Ubuntu | upstream | * | 
| Linux-lts-backport-natty | Ubuntu | lucid | * | 
| Linux-lts-backport-natty | Ubuntu | upstream | * | 
| Linux-lts-backport-oneiric | Ubuntu | upstream | * | 
| Linux-maguro | Ubuntu | saucy | * | 
| Linux-maguro | Ubuntu | upstream | * | 
| Linux-mako | Ubuntu | saucy | * | 
| Linux-mako | Ubuntu | upstream | * | 
| Linux-manta | Ubuntu | saucy | * | 
| Linux-manta | Ubuntu | upstream | * | 
| Linux-mvl-dove | Ubuntu | lucid | * | 
| Linux-mvl-dove | Ubuntu | maverick | * | 
| Linux-mvl-dove | Ubuntu | upstream | * | 
| Linux-ti-omap4 | Ubuntu | maverick | * | 
| Linux-ti-omap4 | Ubuntu | natty | * | 
| Linux-ti-omap4 | Ubuntu | upstream | * |