Debian Security Advisory

DSA-4951-1 bluez -- security update

Date Reported:
07 Aug 2021
Affected Packages:
bluez
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 989614.
In Mitre's CVE dictionary: CVE-2020-26558, CVE-2020-27153, CVE-2021-0129.
More information:

Several vulnerabilities were discovered in Bluez, the Linux Bluetooth protocol stack.

  • CVE-2020-26558

    / CVE-2021-0129

    It was discovered that Bluez does not properly check permissions during pairing operation, which could allow an attacker to impersonate the initiating device.

  • CVE-2020-27153

    Jay LV discovered a double free flaw in the disconnect_cb() routine in the gattool. A remote attacker can take advantage of this flaw during service discovery for denial of service, or potentially, execution of arbitrary code.

For the stable distribution (buster), these problems have been fixed in version 5.50-1.2~deb10u2.

We recommend that you upgrade your bluez packages.

For the detailed security status of bluez please refer to its security tracker page at: https://security-tracker.debian.org/tracker/bluez