Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 9: 2023-0353 Moderate: Addressing BlueZ Injection Threat

mageia
Calendar Grey December 20, 2023
Dist Mageia Esm H88
Mageia 9's most recent security update addresses flaws associated with unapproved Bluetooth connections and risks of possible code execution attacks.
This update fixes the following security issue

Summary

This update fixes the following security issue. Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access (CVE-2023-45866).

References

- https://bugs.mageia.org/show_bug.cgi?id=32604

- https://github.com/skysafe/reblog/tree/main/cve-2023-45866

- https://ubuntu.com/security/notices/USN-6540-1

- https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/profiles/input?id=25a471a83e02e1effb15d5a488b3f0085eaeb675

- https://www.cve.org/CVERecord?id=CVE-2023-45866

Resolution

SRPMS

- 9/core/bluez-5.70-1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 20 Dec 2023
URL: https://advisories.mageia.org/MGASA-2023-0353.html
Type: security
CVE: CVE-2023-45866

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here