cbcvebase.
CVE-2020-27153
published 2020-10-15

CVE-2020-27153: In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of…

PriorityP345high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
4.24%
89.9th percentile
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

Affected

13 ranges
VendorProductVersion rangeFixed in
bluezbluez< 5.555.55
bluezbluez>= 0 < 5.55-15.55-1
bluezbluez>= 0 < 5.55-15.55-1
bluezbluez>= 0 < 5.55-15.55-1
bluezbluez>= 0 < 5.55-15.55-1
bluezbluez>= 0 < 5.48-0ubuntu3.55.48-0ubuntu3.5
bluezbluez>= 0 < 5.53-0ubuntu3.25.53-0ubuntu3.2
bluezbluez>= 0 < 5.37-0ubuntu5.3+esm15.37-0ubuntu5.3+esm1
debianbluez< bluez 5.55-1 (bookworm)bluez 5.55-1 (bookworm)
debiandebian_linux
debiandebian_linux
opensuseleap
opensuseleap

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.