It was discovered that BlueZ incorrectly handled the Discoverable status when a device is powered down. This could result in devices being powered up discoverable, contrary to expectations. This issue only affected Ubuntu 20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause BlueZ to consume resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled disconnects. A remote attacker could possibly use this issue to cause BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
{ "availability": "No subscription required", "binaries": [ { "libbluetooth3": "5.48-0ubuntu3.6", "bluetooth": "5.48-0ubuntu3.6", "bluez-hcidump": "5.48-0ubuntu3.6", "bluez-cups": "5.48-0ubuntu3.6", "bluez-tests": "5.48-0ubuntu3.6", "libbluetooth3-dbg": "5.48-0ubuntu3.6", "bluez-dbg": "5.48-0ubuntu3.6", "libbluetooth-dev": "5.48-0ubuntu3.6", "bluez": "5.48-0ubuntu3.6", "bluez-obexd": "5.48-0ubuntu3.6" } ] }
{ "availability": "No subscription required", "binaries": [ { "libbluetooth3": "5.53-0ubuntu3.4", "bluetooth": "5.53-0ubuntu3.4", "bluez-hcidump": "5.53-0ubuntu3.4", "bluez-cups": "5.53-0ubuntu3.4", "bluez-tests": "5.53-0ubuntu3.4", "libbluetooth3-dbg": "5.53-0ubuntu3.4", "bluez-dbg": "5.53-0ubuntu3.4", "libbluetooth-dev": "5.53-0ubuntu3.4", "bluez": "5.53-0ubuntu3.4", "bluez-obexd": "5.53-0ubuntu3.4" } ] }