USN-7222-1: BlueZ vulnerabilities
Published Jan 22, 2025
·Updated
Lucas Leong discovered that BlueZ incorrectly handled the Phone Book Access profile. If a user were tricked into connecting to a malicious Bluetooth device, a remote attacker could possibly use this issue to execute arbitrary code.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/bluez<5.64-0ubuntu1.4
5.64-0ubuntu1.4
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libbluetooth3<5.64-0ubuntu1.4
5.64-0ubuntu1.4
Ubuntu Ubuntu=22.04
All of the following
ubuntu/bluez<5.53-0ubuntu3.9
5.53-0ubuntu3.9
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libbluetooth3<5.53-0ubuntu3.9
5.53-0ubuntu3.9
Ubuntu Ubuntu=20.04
Event History
Jan 22, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7222-1?
USN-7222-1 has been classified as a high severity vulnerability.
2
How do I fix USN-7222-1?
To fix USN-7222-1, upgrade the BlueZ package to version 5.64-0ubuntu1.4 or higher on Ubuntu 22.04 and to 5.53-0ubuntu3.9 or higher on Ubuntu 20.04.
3
Which software is affected by USN-7222-1?
USN-7222-1 affects BlueZ and libbluetooth3 on Ubuntu versions 22.04 and 20.04.
4
Who discovered USN-7222-1 vulnerability?
The USN-7222-1 vulnerability was discovered by Lucas Leong.
5
What can an attacker achieve with USN-7222-1?
An attacker could potentially execute arbitrary code by exploiting the vulnerability when a user connects to a malicious Bluetooth device.