Your submission was sent successfully! Close

CVE-2020-27153

Published: 15 October 2020

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

Notes

AuthorNote
mdeslaur
per Red Hat, there is currently no known path to code execution
as there is a small time window between the two calls to free()
as such, marking as low priority.
Priority

Low

CVSS 3 base score: 8.6

Status

Package Release Status
bluez
Launchpad, Ubuntu, Debian
bionic
Released (5.48-0ubuntu3.5)
focal
Released (5.53-0ubuntu3.2)
groovy
Released (5.55-0ubuntu1)
hirsute
Released (5.55-0ubuntu1)
impish
Released (5.55-0ubuntu1)
jammy
Released (5.55-0ubuntu1)
precise Does not exist

trusty Does not exist

upstream
Released (5.55-1)
xenial
Released (5.37-0ubuntu5.3+esm1)
Patches:
upstream: https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721a