Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:2081

Опубликовано: 10 мая 2022
Источник: rocky
Оценка: SEVERITY_LOW

Описание

Low: bluez security update

The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (Rocky Enterprise Software Foundation), and pcmcia configuration files. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
bluezx86_643.el8bluez-5.56-3.el8.x86_64.rpm
bluez-hid2hcix86_643.el8bluez-hid2hci-5.56-3.el8.x86_64.rpm
bluez-libsi6863.el8bluez-libs-5.56-3.el8.i686.rpm
bluez-libsx86_643.el8bluez-libs-5.56-3.el8.x86_64.rpm
bluez-obexdx86_643.el8bluez-obexd-5.56-3.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.

CVSS3: 4.3
redhat
больше 3 лет назад

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.

CVSS3: 4.3
nvd
больше 3 лет назад

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.

CVSS3: 4.3
debian
больше 3 лет назад

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a ...

suse-cvrf
почти 2 года назад

Security update for bluez