Stack-based buffer overflow in BlueZ - CVE-2023-44431

 

Stack-based buffer overflow in BlueZ - CVE-2023-44431

Published: December 22, 2023


Vulnerability identifier: #VU84669
CSH Severity: Medium
CVSS v4: 7.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44431
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when handling AVRCP protocol. A remote attacker can trick the victim into connection to a malicious Bluetooth device, trigger a stack-based buffer overflow and execute arbitrary code on the system.

Affected software

BlueZ
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
libell
iwd
bluez (Red Hat package)
bluez
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Dev Spaces
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component

How to mitigate CVE-2023-44431

Install updates from vendor's website.

BlueZ - update to 5.71
libell - update to 0.74-1.fc42
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
iwd - update to 3.4-1.fc42
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
bluez (Red Hat package) - update to 5.72-2.el9
bluez - update to 5.80-1.fc42

External References

Related Security Bulletins