First published: Thu Jun 10 2021(Updated: )
Last updated 24 July 2024
Credit: security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
BlueZ BlueZ | <5.56 | |
debian/bluez | 5.55-3.1+deb11u1 5.55-3.1+deb11u2 5.66-1+deb12u2 5.66-1+deb12u1 5.79-1 |
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/src/gatt-database.c?id=6a50b6aeda78a88eafb177718109c256eec077a6
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-3588.
The affected software is bluez.
The severity of CVE-2021-3588 is not specified.
The vulnerability occurs due to the lack of bounds checks on the 'offset' variable in the cli_feat_read_cb() function.
To fix this vulnerability, update bluez to version 5.53-0ubuntu3.2 or later.