Debian Security Advisory
DSA-4951-1 bluez -- security update
- Date Reported:
- 07 Aug 2021
- Affected Packages:
- bluez
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 989614.
In Mitre's CVE dictionary: CVE-2020-26558, CVE-2020-27153, CVE-2021-0129. - More information:
-
Several vulnerabilities were discovered in Bluez, the Linux Bluetooth protocol stack.
- CVE-2020-26558
It was discovered that Bluez does not properly check permissions during pairing operation, which could allow an attacker to impersonate the initiating device.
- CVE-2020-27153
Jay LV discovered a double free flaw in the disconnect_cb() routine in the gattool. A remote attacker can take advantage of this flaw during service discovery for denial of service, or potentially, execution of arbitrary code.
For the stable distribution (buster), these problems have been fixed in version 5.50-1.2~deb10u2.
We recommend that you upgrade your bluez packages.
For the detailed security status of bluez please refer to its security tracker page at: https://security-tracker.debian.org/tracker/bluez
- CVE-2020-26558