Ubuntu Security Notice 5155-1 - It was discovered that BlueZ incorrectly handled the Discoverable status when a device is powered down. This could result in devices being powered up discoverable, contrary to expectations. This issue only affected Ubuntu 20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. It was discovered that BlueZ incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause BlueZ to consume resources, leading to a denial of service. Various other issues were also addressed.
fb1f4d28536d31077de5fae1a663c61f51e52453558f017d24b62822f6fb50a1
==========================================================================
Ubuntu Security Notice USN-5155-1
November 23, 2021
bluez vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 21.10
- Ubuntu 21.04
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in BlueZ.
Software Description:
- bluez: Bluetooth tools and daemons
Details:
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 21.10:
bluez 5.60-0ubuntu2.1
libbluetooth3 5.60-0ubuntu2.1
Ubuntu 21.04:
bluez 5.56-0ubuntu4.3
libbluetooth3 5.56-0ubuntu4.3
Ubuntu 20.04 LTS:
bluez 5.53-0ubuntu3.4
libbluetooth3 5.53-0ubuntu3.4
Ubuntu 18.04 LTS:
bluez 5.48-0ubuntu3.6
libbluetooth3 5.48-0ubuntu3.6
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5155-1
CVE-2021-3658, CVE-2021-41229, CVE-2021-43400
Package Information:
https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1
https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3
https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4
https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6