CVE-2022-0204: Buffer Overflow
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
Other sources
A heap-based buffer overflow was found in BlueZ in the implementation of the gatt protocol due to an integer overflow.
Upstream commit:
https://github.com/bluez/bluez/commit/591c546c536b42bef696d027f64aa22434f8c3f0
Reference:
https://github.com/bluez/bluez/security/advisories/GHSA-479m-xcq5-9g2q
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0204?
CVE-2022-0204 is a heap overflow vulnerability found in BlueZ versions prior to 5.63.
What is the severity of CVE-2022-0204?
CVE-2022-0204 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2022-0204?
An attacker with local network access could exploit CVE-2022-0204 by passing specially crafted files, causing an application to halt or crash.
Which software versions are affected by CVE-2022-0204?
BlueZ versions prior to 5.63 are affected by CVE-2022-0204.
How can I fix CVE-2022-0204?
To fix CVE-2022-0204, upgrade to BlueZ version 5.63 or later.