Double Free in BlueZ - CVE-2020-27153
Published: October 15, 2020 / Updated: September 29, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker can cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
openEuler
bluez (Alpine package)
bluez (Debian package)
bluez (Red Hat package)
libbluetooth3 (Ubuntu package)
bluez (Ubuntu package)
bluez-help
bluez-debugsource
bluez-libs
bluez-debuginfo
bluez-devel
bluez-cups
bluez
How to mitigate CVE-2020-27153
bluez (Alpine package) - addressed in versions 5.50-r2, 5.50-r5
bluez (Debian package) - update to 5.50-1.2~deb10u2
bluez (Red Hat package) - update to 5.52-4.el8
libbluetooth3 (Ubuntu package) - addressed in versions 5.48-0ubuntu3.5, 5.53-0ubuntu3.2, 5.55-0ubuntu1.2, 5.56-0ubuntu4.1, 5.370ubuntu5.3+esm1
bluez (Ubuntu package) - addressed in versions 5.48-0ubuntu3.5, 5.53-0ubuntu3.2, 5.55-0ubuntu1.2, 5.56-0ubuntu4.1, 5.370ubuntu5.3+esm1
bluez-help - update to 5.54-4
bluez-debugsource - update to 5.54-4
bluez-libs - update to 5.54-4
bluez-debuginfo - update to 5.54-4
bluez-devel - update to 5.54-4
bluez-cups - update to 5.54-4
bluez - update to 5.54-4
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=1884817
- https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721a
- https://github.com/bluez/bluez/commit/5a180f2ec9edfacafd95e5fed20d36fe8e077f07
- https://lists.debian.org/debian-lts-announce/2020/10/msg00022.html
- https://security.gentoo.org/glsa/202011-01