The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
- http://www.redhat.com/support/errata/RHSA-2005-366.html
No PoCs found on GitHub currently.