Security update for bluez
This update for bluez fixes the following issues: - CVE-2019-8921: Fixed heap-based buffer overflow via crafted request (bsc#1193237). - CVE-2019-8922: Fixed heap-based buffer overflow via crafted request (bsc#1193227). - CVE-2020-26558: Fixed vulnerability that may permit a nearby man-in-the-middle attacker to identify the Passkey (bsc#1186463). - CVE-2021-0129: Fixed improper access control (bsc#1186463). - CVE-2021-3658: Fixed adapter incorrectly restoring discoverable state after powered down (bsc#1188859). - CVE-2021-43400: Fixed use-after-free in gatt-database.c (bsc#1192394).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for bluez fixes the following issues: - CVE-2019-8921: Fixed heap-based buffer overflow via crafted request (bsc#1193237). - CVE-2019-8922: Fixed heap-based buffer overflow via crafted request (bsc#1193227). - CVE-2020-26558: Fixed vulnerability that may permit a nearby man-in-the-middle attacker to identify the Passkey (bsc#1186463). - CVE-2021-0129: Fixed improper access control (bsc#1186463). - CVE-2021-3658: Fixed adapter incorrectly restoring discoverable state after powered down (bsc#1188859). - CVE-2021-43400: Fixed use-after-free in gatt-database.c (bsc#1192394).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1186463
- https://bugzilla.suse.com/1188859
- https://bugzilla.suse.com/1192394
- https://bugzilla.suse.com/1193227
- https://bugzilla.suse.com/1193237
- https://www.suse.com/security/cve/CVE-2019-8921
- https://www.suse.com/security/cve/CVE-2019-8922
- https://www.suse.com/security/cve/CVE-2020-26558
- https://www.suse.com/security/cve/CVE-2021-0129
- https://www.suse.com/security/cve/CVE-2021-3658
- https://www.suse.com/security/cve/CVE-2021-43400
- https://www.suse.com/support/update/announcement/2022/suse-su-20223691-1/