It was discovered that BlueZ incorrectly validated certain capabilities and lengths when handling the A2DP profile. A remote attacker could use this issue to cause BlueZ to crash, resulting in a denial of service, or possibly execute arbitrary code.
- https://bugs.mageia.org/show_bug.cgi?id=30556
- https://ubuntu.com/security/notices/USN-5481-1
- 8/core/bluez-5.55-3.5.mga8
Get the latest Linux and open source security news straight to your inbox.