Fedora alert FEDORA-2026-d4eec45564 (bluez)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 43 Update: bluez-5.87-6.fc43 | |
| Date: | Mon, 31 Aug 2026 17:04:55 +0000 | |
| Message-ID: | <20260831170455.5EE7C18E5639@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d4eec45564 2026-08-31 16:58:22.985432+00:00 -------------------------------------------------------------------------------- Name : bluez Product : Fedora 43 Version : 5.87 Release : 6.fc43 URL : http://www.bluez.org/ Summary : Bluetooth utilities Description : Utilities for use in Bluetooth applications: - avinfo - bluemoon - bluetoothctl - bluetoothd - btattach - btmon - hex2hcd - mpris-proxy The BLUETOOTH trademarks are owned by Bluetooth SIG, Inc., U.S.A. -------------------------------------------------------------------------------- Update Information: BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd. A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 26 2026 Bastien Nocera <bnocera@redhat.com> - 5.87-6 - Fix CVE-2026-80185 (Closes: #2524397) * Wed Aug 26 2026 Bastien Nocera <bnocera@redhat.com> - 5.87-5 - Fix CVE-2026-80186 (Closes: #2524148) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2524148 - CVE-2026-80186 bluez: Stack Overflow in name2utf8 causes DoS and potential code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2524148 [ 2 ] Bug #2524397 - CVE-2026-80185 bluez: sdp-xml: BlueZ 5.86: unprivileged-local and adjacent-LE-peer leads to arbitrary code execution as root [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2524397 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d4eec45564' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
