Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Mageia: MGASA-2022-0235 Critical: BlueZ Denial Of Service Threat

mageia
Calendar Grey June 18, 2022
Dist Mageia Esm H88
The recent security patch MGASA-2022-0235 for BlueZ tackles vulnerabilities involving potential remote code execution and denial of service threats.
It was discovered that BlueZ incorrectly validated certain capabilities and lengths when handling the A2DP profile

Summary

It was discovered that BlueZ incorrectly validated certain capabilities and lengths when handling the A2DP profile. A remote attacker could use this issue to cause BlueZ to crash, resulting in a denial of service, or possibly execute arbitrary code.

References

- https://bugs.mageia.org/show_bug.cgi?id=30556

- https://ubuntu.com/security/notices/USN-5481-1

Resolution

SRPMS

- 8/core/bluez-5.55-3.5.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 18 Jun 2022
URL: https://advisories.mageia.org/MGASA-2022-0235.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here