Out-of-bounds read in BlueZ - CVE-2023-51592
Published: December 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when handling AVRCP protocol within the parse_media_folder() function. A remote attacker can trick the victim into connecting to a malicious device, trigger an out-of-bounds read and gain access to sensitive information.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Fedora
libell
iwd
bluez (Red Hat package)
bluez
bluez-cups
bluez-hid2hci
bluez-libs
bluez-libs-devel
bluez-mesh
bluez-obexd
bluez-doc
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Dev Spaces
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
How to mitigate CVE-2023-51592
libell - update to 0.74-1.fc42
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
iwd - update to 3.4-1.fc42
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
bluez (Red Hat package) - update to 5.72-2.el9
bluez - update to 5.80-1.fc42
bluez - update to 5.82-1
bluez-cups - update to 5.82-1
bluez-hid2hci - update to 5.82-1
bluez-libs - update to 5.82-1
bluez-libs-devel - update to 5.82-1
bluez-mesh - update to 5.82-1
bluez-obexd - update to 5.82-1
bluez-doc - update to 5.82-1
External References
Related Security Bulletins
- Multiple vulnerabilities in BlueZ
- Red Hat Enterprise Linux 9 update for bluez
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
- Fedora 42 update for bluez, iwd, libell
- Anolis OS update for bluez