Information on source package bluez

Available versions

ReleaseVersion
buster5.50-1.2~deb10u2
bullseye5.55-3.1
bookworm5.65-1
sid5.65-1

Open issues

BugbusterbullseyebookwormsidDescription
CVE-2022-39177vulnerablevulnerable (no DSA)fixedfixedBlueZ before 5.59 allows physically proximate attackers to cause a den ...
CVE-2022-39176vulnerablevulnerable (no DSA)fixedfixedBlueZ before 5.59 allows physically proximate attackers to obtain sens ...
CVE-2022-0204vulnerable (no DSA)vulnerable (no DSA)fixedfixedA heap overflow vulnerability was found in bluez in versions prior to ...
CVE-2021-43400vulnerable (no DSA)vulnerable (no DSA)fixedfixedAn issue was discovered in gatt-database.c in BlueZ 5.61. A use-after- ...
CVE-2021-41229vulnerable (no DSA)vulnerable (no DSA)fixedfixedBlueZ is a Bluetooth protocol stack for Linux. In affected versions a ...
CVE-2021-3658vulnerable (no DSA)vulnerable (no DSA)fixedfixedbluetoothd from bluez incorrectly saves adapters' Discoverable status ...
CVE-2020-26560vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableBluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0. ...
CVE-2020-26559vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableBluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0. ...
CVE-2020-26557vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableMesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may perm ...
CVE-2019-8922vulnerable (no DSA)fixedfixedfixedA heap-based buffer overflow was discovered in bluetoothd in BlueZ thr ...
CVE-2019-8921vulnerable (no DSA)fixedfixedfixedAn issue was discovered in bluetoothd in BlueZ through 5.48. The vulne ...
CVE-2018-10910vulnerable (no DSA, ignored)fixedfixedfixedA bug in Bluez may allow for the Bluetooth Discoverable state being se ...

Open unimportant issues

BugbusterbullseyebookwormsidDescription
CVE-2016-9918vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump ...
CVE-2016-9917vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "read_n" function in ...
CVE-2016-9804vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "commands_dump" funct ...
CVE-2016-9803vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" ...
CVE-2016-9802vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" fun ...
CVE-2016-9801vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" functi ...
CVE-2016-9800vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" ...
CVE-2016-9799vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" funct ...
CVE-2016-9798vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a use-after-free was identified in "conf_opt" function ...
CVE-2016-9797vulnerablevulnerablevulnerablevulnerableIn BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" functio ...

Resolved issues

BugDescription
CVE-2021-3588The cli_feat_read_cb() function in src/gatt-database.c does not perfor ...
CVE-2021-0129Improper access control in BlueZ may allow an authenticated user to po ...
CVE-2020-27153In BlueZ before 5.55, a double free was found in the gatttool disconne ...
CVE-2020-26558Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification ...
CVE-2020-0556Improper access control in subsystem for BlueZ before version 5.54 may ...
CVE-2017-1000250All versions of the SDP server in BlueZ 5.46 and earlier are vulnerabl ...
CVE-2016-7837Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execut ...

Security announcements

DSA / DLADescription
DLA-2827-1bluez - security update
DSA-4951-1bluez - security update
DLA-2692-1bluez - security update
DLA-2410-1bluez - security update
DLA-2240-1bluez - security update
DSA-4647-1bluez - security update
DLA-1103-1bluez - security update
DSA-3972-1bluez - security update

Search for package or bug name: Reporting problems