Описание
BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.
The specific flaw exists within the handling of the stream endpoints. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29429.
A flaw was found in BlueZ. This vulnerability, a stack-based buffer overflow in the Advanced Audio Distribution Profile (A2DP) stack, allows a network-adjacent attacker to execute arbitrary code. By pairing a malicious Bluetooth device with the target system, an attacker can exploit improper validation of user-supplied data length. Successful exploitation leads to arbitrary code execution with root privileges.
Меры по смягчению последствий
To mitigate this vulnerability, disable the Bluetooth service if it is not required. This can be achieved by stopping and disabling the bluetooth service.
Disabling the Bluetooth service will prevent all Bluetooth functionality on the system. A system reboot may be required for the changes to take full effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bluez | Affected | ||
| Red Hat Enterprise Linux 6 | bluez | Out of support scope | ||
| Red Hat Enterprise Linux 7 | bluez | Affected | ||
| Red Hat Enterprise Linux 8 | bluez | Affected | ||
| Red Hat Enterprise Linux 9 | bluez | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8 High
CVSS3
Связанные уязвимости
(BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerabi ...)
BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the stream endpoints. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29429.
BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability
BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerabi ...
BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the stream endpoints. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29429.
EPSS
8 High
CVSS3