[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] Bluez <5.53 DoS/privilege escalation
From:       Marc Deslauriers <marc.deslauriers () canonical ! com>
Date:       2020-03-13 13:27:29
Message-ID: db191909-53dd-786f-9b28-200e058917f8 () canonical ! com
[Download RAW message or body]

On 2020-03-12 6:55 p.m., Matthew Garrett wrote:
> https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00352.html
> describes a vulnerability in versions below 5.53 of the Bluez
> Bluetooth stack. Intel do not appear to have disclosed this issue to
> distributions in advance, and have not yet made a release that
> includes the fixes. https://patchwork.kernel.org/patch/11428317/ and
> https://patchwork.kernel.org/patch/11428319/ should apply to older
> versions.
> 

I looks like the patches went into the tree after 5.53, so I'm not sure 5.53 is
actually fixed.

Does anyone know if there were any other changes in 5.53 that would mitigate the
issue?

https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=8cdbd3b09f29da29374e2f83369df24228da0ad1
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=3cccdbab2324086588df4ccf5f892fb3ce1f1787

Marc.
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic