Google security researcher Andy Nguyen has disclosed long-awaited details of zero-click vulnerabilities in the Linux Bluetooth subsystem that allow nearby, unauthenticated attackers “to execute arbitrary code with kernel privileges on vulnerable devices”. Nguyen claims that his findings ultimately led to a safer, more stable kernel. . Dubbed ‘BleedingTooth’, the trio of security flaws were found in BlueZ, the open source , official Linux Bluetooth protocol stack found on Linux-based laptops and IoT devices. Google security engineer Andy Nguyen dropped a technical write-up on Twitter on April 6 that exhaustively recounts how he discovered and chained the bugs to achieve remote code execution ( RCE ) on a Dell laptop running Ubuntu 20.04.1 without ‘victim’ interaction. . Explore the BleedingTooth security flaws within Linux Bluetooth that enable remote code execution and examine their potential ramifications.. Linux Bluetooth Security, Remote Code Execution, BlueZ Exploits. . Brittany Day
IBM has admitted to making 'a process error, improper response' to a bug report that identified four vulnerabilities in its enterprise security software, and the tech giant plans to issue an advisory. . IBM Data Risk Manager offers security-focused vulnerability scanning and analytics, to help businesses identify weaknesses in their infrastructure. At least some versions of the Linux-powered suite included four exploitable holes, identified and, at first, privately disclosed by security researcher Pedro Ribeiro at no charge. Three are considered to be critical, and one is high risk. The software flaws can be chained together to achieve unauthenticated remote code execution as root on a vulnerable installation, as described in an advisory Ribeiro published today on GitHub. . Critical vulnerabilities in IBM Data Risk Manager have surfaced, tied to remote execution flaws due to unexpected response anomalies. Discover these security risks and their impacts. IBM Data Risk Manager, security vulnerabilities, remote code execution, data risk management, enterprise security. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.