Lucene search

K
osvGoogleOSV:RLSA-2021:1598
HistoryMay 18, 2021 - 5:37 a.m.

Moderate: bluez security update

2021-05-1805:37:07
Google
osv.dev
5

8.6 High

AI Score

Confidence

High

0.05 Low

EPSS

Percentile

92.9%

The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (Rocky Enterprise Software Foundation), and pcmcia configuration files.

Security Fix(es):

  • bluez: double free in gatttool client disconnect callback handler in src/shared/att.c could lead to DoS or RCE (CVE-2020-27153)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.