UBUNTU-CVE-2020-26558 Published: 8 Jun 2021Last Modified: 9 Sept 2026
Details: Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
References: https://ubuntu.com/security/CVE-2020-26558 , https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/passkey-entry/ , https://kb.cert.org/vuls/id/799380 , https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00517.html , https://ubuntu.com/security/notices/USN-4989-1 , https://ubuntu.com/security/notices/USN-4989-2 , https://ubuntu.com/security/notices/USN-5018-1 , https://ubuntu.com/security/notices/USN-5017-1 , https://ubuntu.com/security/notices/USN-5046-1 , https://ubuntu.com/security/notices/USN-5050-1 , https://ubuntu.com/security/notices/USN-5299-1 , https://ubuntu.com/security/notices/USN-5343-1 , https://www.cve.org/CVERecord?id=CVE-2020-26558
linux-aws
linux-azure
linux-lts-xenial
linux
bluez
linux
linux-aws
linux-aws-hwe
linux-azure
linux-gcp
linux-hwe
linux-kvm
linux-oracle
linux-hwe-edge
linux-fips
linux-fips
bluez
linux
linux-aws
linux-aws-5.4
linux-azure-4.15
linux-azure-5.4
linux-dell300x
linux-gcp-4.15
linux-gcp-5.4
linux-gke-5.4
linux-gkeop-5.4
linux-hwe-5.4
linux-kvm
linux-oracle
linux-oracle-5.4
linux-raspi-5.4
linux-raspi2
linux-snapdragon
linux-aws-5.0
linux-aws-5.3
linux-azure
linux-azure-5.3
linux-azure-edge
linux-gcp
linux-gcp-5.3
linux-gcp-edge
linux-gke-4.15
linux-hwe
linux-hwe-edge
linux-oem
linux-oracle-5.0
linux-oracle-5.3
linux-aws-fips
linux-azure-fips
linux-fips
linux-gcp-fips
linux-aws-fips
linux-azure-fips
linux-fips
linux-gcp-fips
bluez
linux
linux-aws
linux-aws-5.11
linux-aws-5.8
linux-azure
linux-azure-5.11
linux-azure-5.8
linux-bluefield
linux-gcp
linux-gcp-5.11
linux-gcp-5.8
linux-gke
linux-gkeop
linux-hwe-5.11
linux-kvm
linux-oem-5.10
linux-oracle
linux-oracle-5.11
linux-oracle-5.8
linux-raspi
linux-riscv-5.11
linux-azure-fde-5.15
linux-hwe-5.8
linux-oem-5.6
linux-raspi2
linux-riscv
linux-riscv-5.8
linux-aws-fips
linux-azure-fips
linux-fips
linux-gcp-fips
linux-aws-fips
linux-azure-fips
linux-fips
linux-gcp-fips
linux-intel-iot-realtime
linux-realtime
linux-raspi-realtime
Package Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges Type: ECOSYSTEM
Events:
Introduced - 0
Fixed - 4.4.0-1099.104
4.4.0-1002.2
4.4.0-1003.3
4.4.0-1005.5
4.4.0-1006.6
4.4.0-1009.9
4.4.0-1010.10
4.4.0-1011.11
4.4.0-1012.12
4.4.0-1014.14
4.4.0-1016.16
4.4.0-1017.17
4.4.0-1019.19
4.4.0-1022.22
4.4.0-1023.23
4.4.0-1024.25
4.4.0-1025.26
4.4.0-1027.30
4.4.0-1028.31
4.4.0-1029.32
4.4.0-1031.34
4.4.0-1032.35
4.4.0-1034.37
4.4.0-1036.39
4.4.0-1037.40
4.4.0-1038.41
4.4.0-1039.42
4.4.0-1040.43
4.4.0-1042.45
4.4.0-1044.47
4.4.0-1045.48
4.4.0-1046.50
4.4.0-1048.52
4.4.0-1050.54
4.4.0-1052.56
4.4.0-1054.58
4.4.0-1055.59
4.4.0-1056.60
4.4.0-1058.62
4.4.0-1059.63
4.4.0-1060.64
4.4.0-1061.65
4.4.0-1062.66
4.4.0-1064.68
4.4.0-1065.69
4.4.0-1066.70
4.4.0-1067.71
4.4.0-1073.77
4.4.0-1074.78
4.4.0-1075.79
4.4.0-1076.80
4.4.0-1077.81
4.4.0-1078.82
4.4.0-1081.85
4.4.0-1082.86
4.4.0-1083.87
4.4.0-1085.89
4.4.0-1086.90
4.4.0-1087.91
4.4.0-1088.92
4.4.0-1090.94
4.4.0-1091.95
4.4.0-1092.96
4.4.0-1093.97
4.4.0-1094.99
4.4.0-1095.100
4.4.0-1096.101
4.4.0-1097.102
4.4.0-1098.103