Out-of-bounds read in BlueZ - CVE-2023-51589

 

Out-of-bounds read in BlueZ - CVE-2023-51589

Published: December 22, 2023


Vulnerability identifier: #VU84670
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-51589
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition when handling AVRCP protocol within the parse_media_element() function. A remote attacker can trick the victim into connecting to a malicious device, trigger an out-of-bounds read and gain access to sensitive information.

Affected software

BlueZ
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Anolis OS
Fedora
libell
iwd
bluez-libs-devel (Red Hat package)
bluez-obexd-debuginfo (Red Hat package)
bluez-libs-debuginfo (Red Hat package)
bluez-hid2hci-debuginfo (Red Hat package)
bluez-debugsource (Red Hat package)
bluez-cups-debuginfo (Red Hat package)
bluez-cups (Red Hat package)
bluez-debuginfo (Red Hat package)
bluez-obexd
bluez-doc
bluez-libs-devel
bluez-libs
bluez-hid2hci
bluez-cups
bluez
bluez (Red Hat package)
bluez-mesh
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Dev Spaces
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component

How to mitigate CVE-2023-51589

Install updates from vendor's website.

BlueZ - update to 5.71
libell - update to 0.74-1.fc42
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
iwd - update to 3.4-1.fc42
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
bluez-libs-devel (Red Hat package) - update to 5.63-5.el8_10
bluez-obexd-debuginfo (Red Hat package) - update to 5.63-5.el8_10
bluez-libs-debuginfo (Red Hat package) - update to 5.63-5.el8_10
bluez-hid2hci-debuginfo (Red Hat package) - update to 5.63-5.el8_10
bluez-debugsource (Red Hat package) - update to 5.63-5.el8_10
bluez-cups-debuginfo (Red Hat package) - update to 5.63-5.el8_10
bluez-cups (Red Hat package) - update to 5.63-5.el8_10
bluez-debuginfo (Red Hat package) - update to 5.63-5.el8_10
bluez-obexd - addressed in versions 5.63-5.0.1, 5.82-1
bluez-doc - addressed in versions 5.63-5.0.1, 5.82-1
bluez-libs-devel - addressed in versions 5.63-5.0.1, 5.82-1
bluez-libs - addressed in versions 5.63-5.0.1, 5.82-1
bluez-hid2hci - addressed in versions 5.63-5.0.1, 5.82-1
bluez-cups - addressed in versions 5.63-5.0.1, 5.82-1
bluez - addressed in versions 5.63-5.0.1, 5.82-1
bluez (Red Hat package) - update to 5.72-2.el9
bluez - update to 5.80-1.fc42
bluez-mesh - update to 5.82-1

External References

Related Security Bulletins