Linux: BlueZ critical update: handle Bluetooth keystroke injection
Attention, fellow Linux users,
Today, I’m here to alert you of a recent zero-click Bluetooth flaw that enables attackers to secretly pair with devices such as keyboards and inject keystrokes without user interaction or knowledge. This stealthy bug exposes a potential attack vector that could compromise a wide range of devices.
The implications of this vulnerability are far-reaching and significant, given the prevalence of Bluetooth technologies worldwide. The article I link to here contains the technical details you may want to know about this bug.
Read on to learn how to mitigate this flaw and find out about other impactful vulnerabilities recently found and fixed in your open-source programs and applications.
Are your friends and fellow admins aware of this risk? Share this newsletter with them just to be sure! Do you have a Linux security-related topic you'd like to cover for our audience? We welcome contributions from passionate, knowledgeable community members who share our enthusiasm for Linux and security!
Stay safe out there,

BlueZThe DiscoveryA zero-click Bluetooth flaw has been discovered that enables attackers to secretly pair with devices such as keyboards and inject keystrokes without user interaction or knowledge (CVE-2023-45866). |
ThunderbirdThe DiscoveryHave you updated to protect against the significant vulnerabilities recently found in the widely used Thunderbird email client? If a user were tricked into opening a specially crafted website in a browsing context, an attacker could exploit these issues to cause a denial of service, obtain sensitive data, bypass security restrictions, perform cross-site tracing, or execute arbitrary code. |
OpenSSHThe DiscoveryDistros continue to release updates addressing the infamous OoenSSH “Terrapin vulnerability,” which allows a man-in-the-middle (MITM) attacker to access impacted users’ sensitive information in transit, as well as other severe OpenSSH vulnerabilities that were recently discovered. |



