Mageia 2022-0235: bluez security update
Summary
It was discovered that BlueZ incorrectly validated certain capabilities and lengths when handling the A2DP profile. A remote attacker could use this issue to cause BlueZ to crash, resulting in a denial of service, or possibly execute arbitrary code.
References
- https://bugs.mageia.org/show_bug.cgi?id=30556
- https://ubuntu.com/security/notices/USN-5481-1
Resolution
MGASA-2022-0235 - Updated bluez packages fix security vulnerability
SRPMS
- 8/core/bluez-5.55-3.5.mga8