CVE-2020-27153
Published: 15 October 2020
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
Notes
Author | Note |
---|---|
mdeslaur | per Red Hat, there is currently no known path to code execution as there is a small time window between the two calls to free() as such, marking as low priority. |
Priority
Status
Package | Release | Status |
---|---|---|
bluez Launchpad, Ubuntu, Debian |
bionic |
Released
(5.48-0ubuntu3.5)
|
focal |
Released
(5.53-0ubuntu3.2)
|
|
groovy |
Released
(5.55-0ubuntu1)
|
|
hirsute |
Released
(5.55-0ubuntu1)
|
|
impish |
Released
(5.55-0ubuntu1)
|
|
jammy |
Released
(5.55-0ubuntu1)
|
|
trusty |
Does not exist
|
|
upstream |
Released
(5.55-1)
|
|
xenial |
Released
(5.37-0ubuntu5.3+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
Patches: upstream: https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721a |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.6 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | Low |
Integrity impact | Low |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |