Input validation error in Google Android - CVE-2023-45866
Published: December 4, 2023 / Updated: December 19, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to an unspecified vulnerability in Bluetooth implementation. A remote attacker with physical proximity to device can inject keystrokes by spoofing a keyboard and execute arbitrary commands on the system.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
macOS
Slackware Linux
openSUSE Leap
Ubuntu
iPadOS
Apple iOS
openEuler
Fedora
libbluetooth3 (Ubuntu package)
bluez (Ubuntu package)
libbluetooth3-debuginfo
bluez-debugsource
bluez-debuginfo
bluez
libbluetooth3
bluez-devel
bluez-help
bluez-libs
bluez-cups
bluez (Debian package)
bluez-devel-32bit
bluez-test-debuginfo
bluez-cups-debuginfo
libbluetooth3-64bit-debuginfo
libbluetooth3-64bit
bluez-devel-64bit
libbluetooth3-32bit-debuginfo
bluez-deprecated-debuginfo
libbluetooth3-32bit
bluez-auto-enable-devices
bluez-deprecated
bluez-test
bluez (Red Hat package)
bluez-doc
bluez-obexd
bluez-libs-devel
bluez-hid2hci
bluez-zsh-completion
bluez-obexd-debuginfo
net-wireless/bluez
bluez-mesh
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Dev Spaces
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
How to mitigate CVE-2023-45866
macOS - update to 14.2 23C64
iPadOS - update to 17.2 21C62
Apple iOS - update to 17.2 21C62
libbluetooth3 (Ubuntu package) - addressed in versions Ubuntu Pro, 5.53-0ubuntu3.7, 5.64-0ubuntu1.1, 5.66-0ubuntu1.1, 5.68-0ubuntu1.1
bluez (Ubuntu package) - addressed in versions Ubuntu Pro, 5.53-0ubuntu3.7, 5.64-0ubuntu1.1, 5.66-0ubuntu1.1, 5.68-0ubuntu1.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
libbluetooth3-debuginfo - addressed in versions 5.13-5.45.1, 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-debugsource - addressed in versions 5.13-5.45.1, 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-debuginfo - addressed in versions 5.13-5.45.1, 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez - addressed in versions 5.13-5.45.1, 5.62-150400.4.22.1, 5.65-150500.3.14.1
libbluetooth3 - addressed in versions 5.13-5.45.1, 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-devel - addressed in versions 5.13-5.45.1, 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez - update to 5.54-13
bluez-help - update to 5.54-13
bluez-debuginfo - update to 5.54-13
bluez-libs - update to 5.54-13
bluez-debugsource - update to 5.54-13
bluez-cups - update to 5.54-13
bluez-devel - update to 5.54-13
bluez (Debian package) - addressed in versions 5.55-3.1+deb11u1, 5.66-1+deb12u1
bluez - update to 5.62-2
bluez-devel-32bit - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-test-debuginfo - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-cups-debuginfo - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
libbluetooth3-64bit-debuginfo - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
libbluetooth3-64bit - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-devel-64bit - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-cups - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
libbluetooth3-32bit-debuginfo - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-deprecated-debuginfo - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
libbluetooth3-32bit - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-auto-enable-devices - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-deprecated - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez-test - addressed in versions 5.62-150400.4.22.1, 5.65-150500.3.14.1
bluez (Red Hat package) - addressed in versions 5.63-3.el8_10, 5.72-2.el9
bluez-libs - addressed in versions 5.63-3.0.1, 5.71-1
bluez-doc - addressed in versions 5.63-3.0.1, 5.71-1
bluez-obexd - addressed in versions 5.63-3.0.1, 5.71-1
bluez-libs-devel - addressed in versions 5.63-3.0.1, 5.71-1
bluez-hid2hci - addressed in versions 5.63-3.0.1, 5.71-1
bluez-cups - addressed in versions 5.63-3.0.1, 5.71-1
bluez - addressed in versions 5.63-3.0.1, 5.71-1
bluez-zsh-completion - update to 5.65-150500.3.14.1
bluez-obexd-debuginfo - update to 5.65-150500.3.14.1
bluez-obexd - update to 5.65-150500.3.14.1
net-wireless/bluez - update to 5.70-r1
bluez - addressed in versions 5.70-5.fc38, 5.70-5.fc39
bluez - update to 5.71
bluez-mesh - update to 5.71-1
Links to Public Exploits and PoC-codes
- Exploit #11010 - blueXploit (Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)) (December 19, 2024)
- Exploit #10168 - Bluepop (CVE-2023-45866) (July 5, 2024)
- Exploit #9769 - BluetoothDucky (CVE-2023-45866 - BluetoothDucky implementation (Using DuckyScript)) (May 13, 2024)
- Exploit #9637 - BlueDucky (? CVE-2023-45866 - BlueDucky Implementation (Using DuckyScript) ? Unauthenticated Peering Leading to Code Execution (Using HID Keyboard)) (March 22, 2024)
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Android
- Ubuntu update for bluez
- Fedora 38 update for bluez
- Fedora 39 update for bluez
- Multiple vulnerabilities in Apple macOS Sonoma
- Slackware Linux update for bluez
- Debian update for bluez
- Multiple vulnerabilities in Apple iOS 17 and iPadOS 17
- Gentoo update for BlueZ
- openEuler update for bluez
- Amazon Linux AMI update for bluez
- Red Hat Enterprise Linux 9 update for bluez
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Red Hat Enterprise Linux 8 update for bluez
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
- Anolis OS update for bluez
- Anolis OS update for bluez
- SUSE update for bluez
- SUSE update for bluez
- SUSE update for bluez