Google has released details of a high-severity flaw affecting the Bluetooth stack in the Linux kernel versions below Linux 5.9 that support BlueZ. Linux 5.9 was just released two days ago and Intel is recommending in its advisory for the high-severity Bluetooth flaw, CVE-2020-12351, to update the Linux kernel to version 5.9 or later. "Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access," Intel notes in its advisory for CVE-2020-12351. BlueZ is found on Linux-based IoT devices and is the official Linux Bluetooth stack. SEE: Security Awareness and Training policy (TechRepublic Premium) Intel says the BlueZ project is releasing Linux kernel fixes to address the high-severity flaw, as well as fixes for two medium-severity flaws, CVE-2020-12352 and CVE-2020-24490. CVE-2020-12352 is due to improper access control in BlueZ that "may allow an unauthenticated user to potentially enable information disclosure via adjacent access." CVE-2020-24490 refers to BlueZ's lack of proper buffer restrictions that "may allow an unauthenticated user to potentially enable denial of service via adjacent access." Andy Nguyen, a security engineer from Google, reported the bugs to Intel. Researchers from Purdue University last month claimed that BlueZ was also vulnerable to BLESA (Bluetooth Low Energy Spoofing Attack), along with the Fluoride (Android), and the iOS BLE stack. Google has detailed the bugs on the Google Sec...
Google warns of severe 'BleedingTooth' Bluetooth flaw in Linux kernel
ZDNet
·Published Oct 14, 2020
·Updated
Affected Software
3 affected components
Bluez Project Bluez
Linux Kernel<5.9
Linux Kernel>=5.8<5.9
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a severe Bluetooth vulnerability known as 'BleedingTooth' affecting older versions of the Linux kernel.
2
What security implications are discussed?
The article highlights the significant risks associated with the 'BleedingTooth' flaw, which could allow attackers to exploit the Bluetooth stack on affected systems.
3
What versions of the Linux kernel are affected by the 'BleedingTooth' flaw?
The flaw impacts Linux kernel versions below 5.9 that use the BlueZ Bluetooth stack.
4
Which Bluetooth stack is specifically mentioned as vulnerable?
The article specifically mentions the BlueZ Bluetooth stack as being vulnerable to the 'BleedingTooth' flaw.
5
What actions are recommended for users to mitigate the risk of the vulnerability?
The article suggests updating to Linux kernel version 5.9 or later to close the vulnerability associated with 'BleedingTooth'.