Heap-based buffer overflow in BlueZ - CVE-2023-51596
Published: December 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling the Phone Book Access profile. A remote attacker can trick the victim into connection to a malicious Bluetooth device, trigger a heap-based buffer overflow and execute arbitrary code on the system.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
libell
iwd
bluez (Red Hat package)
bluez
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Dev Spaces
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
How to mitigate CVE-2023-51596
libell - update to 0.74-1.fc42
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
iwd - update to 3.4-1.fc42
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
bluez (Red Hat package) - update to 5.72-2.el9
bluez - update to 5.80-1.fc42
External References
Related Security Bulletins
- Multiple vulnerabilities in BlueZ
- Red Hat Enterprise Linux 9 update for bluez
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
- Fedora 42 update for bluez, iwd, libell