bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://gitlab.gnome.org/GNOME/gnome-bluetooth/-/issues/89 | issue tracking third party advisory patch |
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055 | third party advisory patch |
https://github.com/bluez/bluez/commit/b497b5942a8beb8f89ca1c359c54ad67ec843055 | third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=1984728 | issue tracking third party advisory patch |
https://security.netapp.com/advisory/ntap-20220407-0002/ | third party advisory |