USN-6809-1: BlueZ vulnerabilities
It was discovered that BlueZ could be made to dereference invalid memory. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-3563) It was discovered that BlueZ could be made to write out of bounds. If a user were tricked into connecting to a malicious device, an attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2023-27349)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6809-1?
The severity of USN-6809-1 is classified as a potential denial of service vulnerability affecting BlueZ on Ubuntu 22.04 LTS.
How do I fix USN-6809-1?
To fix USN-6809-1, update the BlueZ package to version 5.64-0ubuntu1.3 or later on affected Ubuntu systems.
Which systems are impacted by USN-6809-1?
USN-6809-1 specifically affects Ubuntu 22.04 LTS and earlier versions with the mentioned vulnerable packages.
What packages are directly affected by USN-6809-1?
The affected packages in USN-6809-1 include bluez, bluez-tests, and libbluetooth3.
Can USN-6809-1 be exploited remotely?
Yes, an attacker may exploit the USN-6809-1 vulnerability remotely to cause a denial of service.