USN-5155-1: BlueZ vulnerabilities
23 November 2021
Several security issues were fixed in BlueZ.
- bluez - Bluetooth tools and daemons
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.