Heap-based buffer overflow in BlueZ - CVE-2023-50229
Published: December 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the handling of the Phone Book Access profile. A remote attacker on the local network can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
SmartFabric Storage Software
OpenShift API for Data Protection (OADP)
OpenManage Network Integration (OMNI)
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Red Hat OpenShift Dev Spaces
bluez-devel
libbluetooth3-debuginfo
bluez
libbluetooth3
bluez-debuginfo
bluez-debugsource
libbluetooth3 (Ubuntu package)
bluez (Ubuntu package)
bluez-libs
bluez-cups
bluez-help
bluez-devel-64bit
libbluetooth3-64bit-debuginfo
libbluetooth3-64bit
bluez-devel-32bit
libbluetooth3-32bit
libbluetooth3-32bit-debuginfo
bluez-auto-enable-devices
bluez-test
bluez-test-debuginfo
bluez-deprecated-debuginfo
bluez-deprecated
bluez-cups-debuginfo
bluez-obexd-debuginfo
bluez-obexd
bluez-zsh-completion
bluez (Red Hat package)
How to mitigate CVE-2023-50229
SmartFabric Storage Software - update to 1.4.3
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
OpenManage Network Integration (OMNI) - update to 3.7
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
watsonx Assistant Cartridge - update to 5.1.1
bluez-devel - addressed in versions 5.48-150000.5.54.1, 5.48-150200.13.30.1, 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
libbluetooth3-debuginfo - addressed in versions 5.48-150000.5.54.1, 5.48-150200.13.30.1, 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez - addressed in versions 5.48-150000.5.54.1, 5.48-150200.13.30.1, 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
libbluetooth3 - addressed in versions 5.48-150000.5.54.1, 5.48-150200.13.30.1, 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-debuginfo - addressed in versions 5.48-150000.5.54.1, 5.48-150200.13.30.1, 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-debugsource - addressed in versions 5.48-150000.5.54.1, 5.48-150200.13.30.1, 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
libbluetooth3 (Ubuntu package) - addressed in versions 5.53-0ubuntu3.9, 5.64-0ubuntu1.4
bluez (Ubuntu package) - addressed in versions 5.53-0ubuntu3.9, 5.64-0ubuntu1.4
bluez-devel - update to 5.54-14
bluez - update to 5.54-14
bluez-libs - update to 5.54-14
bluez-cups - update to 5.54-14
bluez-debuginfo - update to 5.54-14
bluez-debugsource - update to 5.54-14
bluez-help - update to 5.54-14
bluez-devel-64bit - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
libbluetooth3-64bit-debuginfo - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
libbluetooth3-64bit - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-devel-32bit - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
libbluetooth3-32bit - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
libbluetooth3-32bit-debuginfo - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-auto-enable-devices - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-test - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-test-debuginfo - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-deprecated-debuginfo - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-deprecated - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-cups-debuginfo - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-cups - addressed in versions 5.55-150300.3.28.1, 5.62-150400.4.19.1, 5.65-150500.3.6.1
bluez-obexd-debuginfo - update to 5.65-150500.3.6.1
bluez-obexd - update to 5.65-150500.3.6.1
bluez-zsh-completion - update to 5.65-150500.3.6.1
bluez (Red Hat package) - update to 5.72-2.el9
External References
Related Security Bulletins
- Multiple vulnerabilities in BlueZ
- SUSE update for bluez
- SUSE update for bluez
- SUSE update for bluez
- SUSE update for bluez
- SUSE update for bluez
- openEuler update for bluez
- Red Hat Enterprise Linux 9 update for bluez
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Ubuntu update for bluez
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
- Dell SmartFabric Storage Software update for third-party components