SUSE-SU-2022:3687-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3687-1
SUSE-SU-2022:3687-1
Summary: Security update for bluez
Details: This update for bluez fixes the following issues: - CVE-2021-0129: Fixed improper access control (bsc#1186463). - CVE-2020-26558: Fixed vulnerability that may permit a nearby man-in-the-middle attacker to identify the Passkey (bsc#1186463). - CVE-2019-8921: Fixed heap-based buffer overflow via crafted request (bsc#1193237). - CVE-2019-8922: Fixed heap-based buffer overflow via crafted request (bsc#1193227). - CVE-2021-3658: Fixed adapter incorrectly restoring discoverable state after powered down (bsc#1188859). - CVE-2021-43400: Fixed use-after-free in gatt-database.c (bsc#1192394).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223687-1/, https://bugzilla.suse.com/1186463, https://bugzilla.suse.com/1188859, https://bugzilla.suse.com/1192394, https://bugzilla.suse.com/1193227, https://bugzilla.suse.com/1193237, https://www.suse.com/security/cve/CVE-2019-8921, https://www.suse.com/security/cve/CVE-2019-8922, https://www.suse.com/security/cve/CVE-2020-26558, https://www.suse.com/security/cve/CVE-2021-0129, https://www.suse.com/security/cve/CVE-2021-3658, https://www.suse.com/security/cve/CVE-2021-43400
Affected packages
Package
Name: bluez
Purl: pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
