The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.