First published: Wed Jun 16 2021(Updated: )
It was discovered that BlueZ incorrectly checked certain permissions when pairing. A local attacker could possibly use this issue to impersonate devices. (CVE-2020-26558) Jay LV discovered that BlueZ incorrectly handled redundant disconnect MGMT events. A local attacker could use this issue to cause BlueZ to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-27153) Ziming Zhang discovered that BlueZ incorrectly handled certain array indexes. A local attacker could use this issue to cause BlueZ to crash, resulting in a denial of service, or possibly obtain sensitive information. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-3588)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libbluetooth3 | <5.56-0ubuntu4.1 | 5.56-0ubuntu4.1 |
=21.04 | ||
All of | ||
ubuntu/bluez | <5.56-0ubuntu4.1 | 5.56-0ubuntu4.1 |
=21.04 | ||
All of | ||
ubuntu/libbluetooth3 | <5.55-0ubuntu1.2 | 5.55-0ubuntu1.2 |
=20.10 | ||
All of | ||
ubuntu/bluez | <5.55-0ubuntu1.2 | 5.55-0ubuntu1.2 |
=20.10 | ||
All of | ||
ubuntu/libbluetooth3 | <5.53-0ubuntu3.2 | 5.53-0ubuntu3.2 |
=20.04 | ||
All of | ||
ubuntu/bluez | <5.53-0ubuntu3.2 | 5.53-0ubuntu3.2 |
=20.04 | ||
All of | ||
ubuntu/libbluetooth3 | <5.48-0ubuntu3.5 | 5.48-0ubuntu3.5 |
=18.04 | ||
All of | ||
ubuntu/bluez | <5.48-0ubuntu3.5 | 5.48-0ubuntu3.5 |
=18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID of this security advisory is USN-4989-1.
The severity of CVE-2020-26558 is not specified in the security advisory.
The severity of CVE-2020-27153 is not specified in the security advisory.
To fix the BlueZ vulnerabilities, you should update the affected software to the recommended versions mentioned in the security advisory.
You can find more information about the BlueZ vulnerabilities in the references section of the security advisory.