An update that solves one vulnerability can now be installed.. # Security update for bluez Announcement ID: SUSE-SU-2026:20041-1 Release Date: 2026-01-08T15:04:11Z Rating: moderate References: * bsc#1217877 Cross-References: * CVE-2023-45866 CVSS scores: * CVE-2023-45866 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45866 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for bluez fixes the following issues: * CVE-2023-45866: keystroke injection and arbitrary command execution via HID device connections (bsc#1217877). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-547=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libbluetooth3-debuginfo-5.70-2.1 * libbluetooth3-5.70-2.1 * bluez-debugsource-5.70-2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45866.html * https://bugzilla.suse.com/show_bug.cgi?id=1217877 . Patch for CVE-2023-45866 resolves moderate keystroke injection risk in SUSE Linux Micro.. SUSE Linux, bluez, patch management, command execution, security advisory. . LinuxSecurity.com Team
* bsc#1217877 Cross-References: * CVE-2023-45866 . # Security update for bluez Announcement ID: SUSE-SU-2025:20804-1 Release Date: 2025-10-01T13:48:02Z Rating: moderate References: * bsc#1217877 Cross-References: * CVE-2023-45866 CVSS scores: * CVE-2023-45866 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45866 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for bluez fixes the following issues: * CVE-2023-45866: Fixed unauthorized HID device connections allowing keystroke injection and arbitrary commands execution (bsc#1217877) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-293=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libbluetooth3-5.70-slfo.1.1_2.1 * libbluetooth3-debuginfo-5.70-slfo.1.1_2.1 * bluez-debugsource-5.70-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45866.html * https://bugzilla.suse.com/show_bug.cgi?id=1217877 . A moderate security update for bluez in SUSE Linux Micro 6.1 addressing CVE-2023-45866 keystroke injection threat.. SUSE update, bluez security, CVE-2023-45866, Bluetooth security, keystroke injection. . LinuxSecurity.com Team
* bsc#1217877 Cross-References: * CVE-2023-45866 . # Security update for bluez Announcement ID: SUSE-SU-2025:03590-1 Release Date: 2025-10-13T12:59:08Z Rating: moderate References: * bsc#1217877 Cross-References: * CVE-2023-45866 CVSS scores: * CVE-2023-45866 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45866 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for bluez fixes the following issues: * CVE-2023-45866: keystroke injection and arbitrary command execution via HID device connections (bsc#1217877). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-3590=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * bluez-debugsource-5.13-5.45.1 * bluez-debuginfo-5.13-5.45.1 * bluez-5.13-5.45.1 * libbluetooth3-5.13-5.45.1 * bluez-devel-5.13-5.45.1 * libbluetooth3-debuginfo-5.13-5.45.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45866.html * https://bugzilla.suse.com/show_bug.cgi?id=1217877 . SUSE issue with bluez allows keystroke injection and remote command execution; patch available for vulnerabilities.. SUSE Bluez Security Moderate Keystroke Injection Patch. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for bluez Announcement ID: SUSE-SU-2025:03277-1 Release Date: 2025-09-19T12:18:50Z Rating: moderate References: * bsc#1217877 Cross-References: * CVE-2023-45866 CVSS scores: * CVE-2023-45866 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45866 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for bluez fixes the following issues: * CVE-2023-45866: keystroke injection and arbitrary command execution via HID device connections (bsc#1217877). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3277=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3277=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3277=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3277=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3277=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libbluetooth3-5.62-150400.4.22.1 * libbluetooth3-debuginfo-5.62-150400.4.22.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libbluetooth3-5.62-150400.4.22.1 * libbluetooth3-debuginfo-5.62-150400.4.22.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * bluez-debugsource-5.62-150400.4.22.1 *libbluetooth3-debuginfo-5.62-150400.4.22.1 * bluez-debuginfo-5.62-150400.4.22.1 * libbluetooth3-5.62-150400.4.22.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * bluez-debugsource-5.62-150400.4.22.1 * libbluetooth3-debuginfo-5.62-150400.4.22.1 * bluez-debuginfo-5.62-150400.4.22.1 * libbluetooth3-5.62-150400.4.22.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libbluetooth3-debuginfo-5.62-150400.4.22.1 * bluez-test-debuginfo-5.62-150400.4.22.1 * libbluetooth3-5.62-150400.4.22.1 * bluez-cups-debuginfo-5.62-150400.4.22.1 * bluez-deprecated-debuginfo-5.62-150400.4.22.1 * bluez-debugsource-5.62-150400.4.22.1 * bluez-debuginfo-5.62-150400.4.22.1 * bluez-5.62-150400.4.22.1 * bluez-cups-5.62-150400.4.22.1 * bluez-test-5.62-150400.4.22.1 * bluez-deprecated-5.62-150400.4.22.1 * bluez-devel-5.62-150400.4.22.1 * openSUSE Leap 15.4 (noarch) * bluez-auto-enable-devices-5.62-150400.4.22.1 * openSUSE Leap 15.4 (x86_64) * libbluetooth3-32bit-5.62-150400.4.22.1 * bluez-devel-32bit-5.62-150400.4.22.1 * libbluetooth3-32bit-debuginfo-5.62-150400.4.22.1 * openSUSE Leap 15.4 (aarch64_ilp32) * bluez-devel-64bit-5.62-150400.4.22.1 * libbluetooth3-64bit-5.62-150400.4.22.1 * libbluetooth3-64bit-debuginfo-5.62-150400.4.22.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45866.html * https://bugzilla.suse.com/show_bug.cgi?id=1217877 . This bulletin highlights a significant risk notification for redz, encompassing threat specifics and guidelines for patch implementation.. SUSE Linux, bluez, security fix, keystroke injection, command execution. . LinuxSecurity.com Team
* bsc#1217877 Cross-References: * CVE-2023-45866 . # Security update for bluez Announcement ID: SUSE-SU-2025:03277-1 Release Date: 2025-09-19T12:18:50Z Rating: moderate References: * bsc#1217877 Cross-References: * CVE-2023-45866 CVSS scores: * CVE-2023-45866 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45866 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for bluez fixes the following issues: * CVE-2023-45866: keystroke injection and arbitrary command execution via HID device connections (bsc#1217877). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3277=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3277=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3277=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3277=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3277=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libbluetooth3-5.62-150400.4.22.1 * libbluetooth3-debuginfo-5.62-150400.4.22.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libbluetooth3-5.62-150400.4.22.1 * libbluetooth3-debuginfo-5.62-150400.4.22.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * bluez-debugsource-5.62-150400.4.22.1 *libbluetooth3-debuginfo-5.62-150400.4.22.1 * bluez-debuginfo-5.62-150400.4.22.1 * libbluetooth3-5.62-150400.4.22.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * bluez-debugsource-5.62-150400.4.22.1 * libbluetooth3-debuginfo-5.62-150400.4.22.1 * bluez-debuginfo-5.62-150400.4.22.1 * libbluetooth3-5.62-150400.4.22.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libbluetooth3-debuginfo-5.62-150400.4.22.1 * bluez-test-debuginfo-5.62-150400.4.22.1 * libbluetooth3-5.62-150400.4.22.1 * bluez-cups-debuginfo-5.62-150400.4.22.1 * bluez-deprecated-debuginfo-5.62-150400.4.22.1 * bluez-debugsource-5.62-150400.4.22.1 * bluez-debuginfo-5.62-150400.4.22.1 * bluez-5.62-150400.4.22.1 * bluez-cups-5.62-150400.4.22.1 * bluez-test-5.62-150400.4.22.1 * bluez-deprecated-5.62-150400.4.22.1 * bluez-devel-5.62-150400.4.22.1 * openSUSE Leap 15.4 (noarch) * bluez-auto-enable-devices-5.62-150400.4.22.1 * openSUSE Leap 15.4 (x86_64) * libbluetooth3-32bit-5.62-150400.4.22.1 * bluez-devel-32bit-5.62-150400.4.22.1 * libbluetooth3-32bit-debuginfo-5.62-150400.4.22.1 * openSUSE Leap 15.4 (aarch64_ilp32) * bluez-devel-64bit-5.62-150400.4.22.1 * libbluetooth3-64bit-5.62-150400.4.22.1 * libbluetooth3-64bit-debuginfo-5.62-150400.4.22.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45866.html * https://bugzilla.suse.com/show_bug.cgi?id=1217877 . Enhancement for bluez addresses CVE-2023-45866 flaw in SUSE Linux for elevated protection.. bluez security update,CVE-2023-45866,openSUSE Leap 15.4,SUSE Linux Micro security. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for bluez Announcement ID: SUSE-SU-2025:03269-1 Release Date: 2025-09-18T11:09:47Z Rating: moderate References: * bsc#1217877 Cross-References: * CVE-2023-45866 CVSS scores: * CVE-2023-45866 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45866 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for bluez fixes the following issues: * CVE-2023-45866: keystroke injection and arbitrary command execution via HID device connections (bsc#1217877). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-3269=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-3269=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * bluez-cups-5.65-150500.3.14.1 * bluez-debugsource-5.65-150500.3.14.1 * bluez-devel-5.65-150500.3.14.1 * libbluetooth3-debuginfo-5.65-150500.3.14.1 * bluez-5.65-150500.3.14.1 * bluez-obexd-debuginfo-5.65-150500.3.14.1 * bluez-debuginfo-5.65-150500.3.14.1 * bluez-cups-debuginfo-5.65-150500.3.14.1 * bluez-deprecated-5.65-150500.3.14.1 * libbluetooth3-5.65-150500.3.14.1 * bluez-obexd-5.65-150500.3.14.1 * bluez-deprecated-debuginfo-5.65-150500.3.14.1 * bluez-test-5.65-150500.3.14.1 * bluez-test-debuginfo-5.65-150500.3.14.1 * openSUSE Leap 15.5 (noarch) * bluez-zsh-completion-5.65-150500.3.14.1 * bluez-auto-enable-devices-5.65-150500.3.14.1 * openSUSE Leap 15.5 (x86_64) * libbluetooth3-32bit-5.65-150500.3.14.1 *bluez-devel-32bit-5.65-150500.3.14.1 * libbluetooth3-32bit-debuginfo-5.65-150500.3.14.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libbluetooth3-64bit-debuginfo-5.65-150500.3.14.1 * bluez-devel-64bit-5.65-150500.3.14.1 * libbluetooth3-64bit-5.65-150500.3.14.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * bluez-debugsource-5.65-150500.3.14.1 * bluez-debuginfo-5.65-150500.3.14.1 * libbluetooth3-5.65-150500.3.14.1 * libbluetooth3-debuginfo-5.65-150500.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45866.html * https://bugzilla.suse.com/show_bug.cgi?id=1217877 . Notice regarding BlueZ addressing recent keystroke injection vulnerabilities. Urgent application of patches advised to maintain system integrity and security.. openSUSE bluez patch update security. . LinuxSecurity.com Team
* bsc#1217877 Cross-References: * CVE-2023-45866 . # Security update for bluez Announcement ID: SUSE-SU-2025:03269-1 Release Date: 2025-09-18T11:09:47Z Rating: moderate References: * bsc#1217877 Cross-References: * CVE-2023-45866 CVSS scores: * CVE-2023-45866 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45866 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for bluez fixes the following issues: * CVE-2023-45866: keystroke injection and arbitrary command execution via HID device connections (bsc#1217877). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-3269=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-3269=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * bluez-cups-5.65-150500.3.14.1 * bluez-debugsource-5.65-150500.3.14.1 * bluez-devel-5.65-150500.3.14.1 * libbluetooth3-debuginfo-5.65-150500.3.14.1 * bluez-5.65-150500.3.14.1 * bluez-obexd-debuginfo-5.65-150500.3.14.1 * bluez-debuginfo-5.65-150500.3.14.1 * bluez-cups-debuginfo-5.65-150500.3.14.1 * bluez-deprecated-5.65-150500.3.14.1 * libbluetooth3-5.65-150500.3.14.1 * bluez-obexd-5.65-150500.3.14.1 * bluez-deprecated-debuginfo-5.65-150500.3.14.1 * bluez-test-5.65-150500.3.14.1 * bluez-test-debuginfo-5.65-150500.3.14.1 * openSUSE Leap 15.5 (noarch) * bluez-zsh-completion-5.65-150500.3.14.1 * bluez-auto-enable-devices-5.65-150500.3.14.1 * openSUSE Leap 15.5 (x86_64) * libbluetooth3-32bit-5.65-150500.3.14.1 * bluez-devel-32bit-5.65-150500.3.14.1 *libbluetooth3-32bit-debuginfo-5.65-150500.3.14.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libbluetooth3-64bit-debuginfo-5.65-150500.3.14.1 * bluez-devel-64bit-5.65-150500.3.14.1 * libbluetooth3-64bit-5.65-150500.3.14.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * bluez-debugsource-5.65-150500.3.14.1 * bluez-debuginfo-5.65-150500.3.14.1 * libbluetooth3-5.65-150500.3.14.1 * libbluetooth3-debuginfo-5.65-150500.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45866.html * https://bugzilla.suse.com/show_bug.cgi?id=1217877 . A recent security patch for BlueZ resolves vulnerabilities linked to unauthorized keystroke manipulation and command execution flaws in openSUSE and SUSE Linux distributions.. BlueZ Update, SUSE Security Advisory, OpenSUSE Fix, Command Execution Issue. . LinuxSecurity.com Team
New bluez packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] bluez (SSA:2023-348-01) New bluez packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/bluez-5.71-i586-1_slack15.0.txz: Upgraded. This update fixes a security issue: It may have been possible for an attacker within Bluetooth range to inject keystrokes (and possibly execute commands) while devices were discoverable. Thanks to marav for the heads-up. For more information, see: https://www.cve.org/CVERecord?id=CVE-2023-45866 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: f59a88ade851b78edbadf0ec910d83e1 bluez-5.71-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 3ed936ff00a912cd10407733326671ef bluez-5.71-x86_64-1_slack15.0.txz Slackware -current package: 6bc0e55e55d4e9c8a41cccf1c1c97232 n/bluez-5.71-i586-1.txz Slackware x86_64 -current package: f31302d1c2ec6774f06cb55ba42a8ea1 n/bluez-5.71-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg bluez-5.71-i586-1_slack15.0.txz +-----+ . New enhancements for BlueZ in Slackware 15.0 tackle a significant keystroke injection loophole. Comprehensive installation instructions have been provided.. Slackware Bluez Update,Bluetooth Security Fix,SecurityAdvisory,Package Upgrade. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.