Information on source package bluez

Available versions

ReleaseVersion
stretch5.43-2+deb9u2
stretch (security)5.43-2+deb9u5
buster5.50-1.2~deb10u2
bullseye5.55-3.1
bookworm5.61-1
sid5.61-1

Open issues

BugstretchbusterbullseyebookwormsidDescription
CVE-2021-43400vulnerable (no DSA, ignored)vulnerablevulnerablevulnerablevulnerableAn issue was discovered in gatt-database.c in BlueZ 5.61. A use-after- ...
CVE-2021-41229fixedvulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableBlueZ is a Bluetooth protocol stack for Linux. In affected versions a ...
CVE-2021-3658fixedvulnerable (no DSA)vulnerable (no DSA)fixedfixed
CVE-2019-8922fixedvulnerablefixedfixedfixedA heap-based buffer overflow was discovered in bluetoothd in BlueZ thr ...
CVE-2019-8921fixedvulnerablefixedfixedfixedAn issue was discovered in bluetoothd in BlueZ through 5.48. The vulne ...
CVE-2018-10910vulnerable (no DSA, ignored)vulnerable (no DSA, ignored)fixedfixedfixedA bug in Bluez may allow for the Bluetooth Discoverable state being se ...

Open unimportant issues

BugstretchbusterbullseyebookwormsidDescription
CVE-2016-9918vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump ...
CVE-2016-9917vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "read_n" function in ...
CVE-2016-9804vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "commands_dump" funct ...
CVE-2016-9803vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" ...
CVE-2016-9802vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" fun ...
CVE-2016-9801vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" functi ...
CVE-2016-9800vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" ...
CVE-2016-9799vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" funct ...
CVE-2016-9798vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a use-after-free was identified in "conf_opt" function ...
CVE-2016-9797vulnerablevulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" functio ...

Resolved issues

BugDescription
CVE-2021-3588The cli_feat_read_cb() function in src/gatt-database.c does not perfor ...
CVE-2021-0129Improper access control in BlueZ may allow an authenticated user to po ...
CVE-2020-27153In BlueZ before 5.55, a double free was found in the gatttool disconne ...
CVE-2020-26558Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification ...
CVE-2020-0556Improper access control in subsystem for BlueZ before version 5.54 may ...
CVE-2017-1000250All versions of the SDP server in BlueZ 5.46 and earlier are vulnerabl ...
CVE-2016-7837Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execut ...

Security announcements

DSA / DLADescription
DLA-2827-1bluez - security update
DSA-4951-1bluez - security update
DLA-2692-1bluez - security update
DLA-2410-1bluez - security update
DLA-2240-1bluez - security update
DSA-4647-1bluez - security update
DLA-1103-1bluez - security update
DSA-3972-1bluez - security update

Search for package or bug name: Reporting problems