USN-6742-1: Linux kernel vulnerabilities
Daniele Antonioli discovered that the Secure Simple Pairing and Secure Connections pairing in the Bluetooth protocol could allow an unauthenticated user to complete authentication without pairing credentials. A physically proximate attacker placed between two Bluetooth devices could use this to subsequently impersonate one of the paired devices. (CVE-2023-24023) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6742-1?
The severity of USN-6742-1 is classified as high due to potential unauthorized access by an unauthenticated user.
How do I fix USN-6742-1?
To fix USN-6742-1, you should update your system to the recommended version of the affected packages as specified in the advisory.
What systems are affected by USN-6742-1?
USN-6742-1 affects Ubuntu 22.04 installations that use specific kernel images vulnerable to this Bluetooth pairing vulnerability.
Can USN-6742-1 be exploited remotely?
USN-6742-1 requires physical proximity, meaning an attacker must be near the vulnerable devices to exploit the vulnerability.
Is there a known solution for USN-6742-1?
Yes, the solution involves upgrading to the patched versions of the affected Linux kernel images mentioned in the advisory.