BlueZ: Security bypass A vulnerability in BlueZ might allow remote attackers to bypass security restrictions. bluez 2020-03-25 2020-03-25 712292 remote 5.54 5.54

Set of tools to manage Bluetooth devices for Linux.

It was discovered that the HID and HOGP profiles implementations in BlueZ did not specifically require bonding between the device and the host.

A remote attacker with adjacent access could impersonate an existing HID device, cause a Denial of Service condition or escalate privileges.

There is no known workaround at this time.

All BlueZ users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-wireless/bluez-5.54"
CVE-2020-0556 whissi whissi