CVE-2020-27153: Double Free
A double-free vulnerability was found in bluez-5.54's gatttool disconnectcb() routine from /src/shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
References:
1. https://github.com/bluez/bluez/commit/5a180f2ec9edfacafd95e5fed20d36fe8e077f07 2. https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721a
Other sources
In BlueZ before 5.55, a double free was found in the gatttool disconnectcb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-27153?
CVE-2020-27153 is a vulnerability in BlueZ before 5.55 that allows a remote attacker to cause a denial of service or execute arbitrary code.
What is the severity of CVE-2020-27153?
CVE-2020-27153 has a severity rating of medium, with a severity value of 4.
How does CVE-2020-27153 impact the affected software?
CVE-2020-27153 affects BlueZ versions before 5.55, potentially leading to a denial of service or code execution during service discovery.
How can I fix CVE-2020-27153?
To fix CVE-2020-27153, update to version 5.55-0ubuntu1 for Ubuntu, 5.55 for Red Hat, or follow the appropriate update instructions for your distribution.
Where can I find more information about CVE-2020-27153?
More information about CVE-2020-27153 can be found in the references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1884817) and [GitHub commits](https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721a, https://github.com/bluez/bluez/commit/5a180f2ec9edfacafd95e5fed20d36fe8e077f07).