=========================================================================Ubuntu Security Notice USN-5183-1
December 08, 2021

bluez vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

BlueZ could be made to crash or run programs if it received specially
crafted traffic.

Software Description:
- bluez: Bluetooth tools and daemons

Details:

Julian Rauchberger discovered that BlueZ incorrectly handled memory when
processing SDP attribute requests. A remote attacker could use this issue
to cause BlueZ to crash, leading to a denial of service, or possibly
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  bluez                           5.48-0ubuntu3.7
  libbluetooth3                   5.48-0ubuntu3.7

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5183-1
  CVE-2019-8922

Package Information:
  https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.7

Ubuntu 5183-1: BlueZ vulnerability

December 8, 2021
BlueZ could be made to crash or run programs if it received specially crafted traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: bluez 5.48-0ubuntu3.7 libbluetooth3 5.48-0ubuntu3.7 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5183-1

CVE-2019-8922

Severity
December 08, 2021

Package Information

https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.7

Related News