CVE-2020-27153
published 2020-10-15CVE-2020-27153: In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of…
PriorityP345high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
4.24%
89.9th percentile
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | < 5.55 | 5.55 |
| bluez | bluez | >= 0 < 5.55-1 | 5.55-1 |
| bluez | bluez | >= 0 < 5.55-1 | 5.55-1 |
| bluez | bluez | >= 0 < 5.55-1 | 5.55-1 |
| bluez | bluez | >= 0 < 5.55-1 | 5.55-1 |
| bluez | bluez | >= 0 < 5.48-0ubuntu3.5 | 5.48-0ubuntu3.5 |
| bluez | bluez | >= 0 < 5.53-0ubuntu3.2 | 5.53-0ubuntu3.2 |
| bluez | bluez | >= 0 < 5.37-0ubuntu5.3+esm1 | 5.37-0ubuntu5.3+esm1 |
| debian | bluez | < bluez 5.55-1 (bookworm) | bluez 5.55-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2021-06-16·CVSS 4.2
CVE-2020-26558 [MEDIUM] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: Several security issues were fixed in BlueZ.
USN-4989-1 fixed several vulnerabilities in BlueZ. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that BlueZ incorrectly checked certain permissions when
pairing. A local attacker could possibly use this issue to impersonate
devices. (CVE-2020-26558)
Jay LV discovered that BlueZ incorrectly handled redundant disconnect MGMT
events. A local attacker could use this issue to cause BlueZ to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-27153)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2021-06-16·CVSS 4.2
CVE-2021-3588 [MEDIUM] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: Several security issues were fixed in BlueZ.
It was discovered that BlueZ incorrectly checked certain permissions when
pairing. A local attacker could possibly use this issue to impersonate
devices. (CVE-2020-26558)
Jay LV discovered that BlueZ incorrectly handled redundant disconnect MGMT
events. A local attacker could use this issue to cause BlueZ to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-27153)
Ziming Zhang discovered that BlueZ incorrectly handled certain array
indexes. A local attacker could use this issue to cause BlueZ to crash,
resulting in a denial of service, or possibly obtain sensitive information.
This issue only affected Ubu
Red Hat
bluez: double free in gatttool client disconnect callback handler in src/shared/att.c could lead to DoS or RCE
vendor_redhat·2020-09-06·CVSS 8.6
CVE-2020-27153 [HIGH] CWE-416 bluez: double free in gatttool client disconnect callback handler in src/shared/att.c could lead to DoS or RCE
bluez: double free in gatttool client disconnect callback handler in src/shared/att.c could lead to DoS or RCE
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
Mitigation: This flaw can be mitigated by only connecting the gatttool client to trusted GATT servers/devices. The flaw is in the service discovery which occurs after a Bluetoth Low Energy (BLE) connection has been established to a device. A secondary mitigation for this flaw is to disable bluetooth. Instructions on disabling bluetooth in Red Hat Enterprise Linux are available at: https://access.redhat.com/solutions/2682931
Pack
Debian
CVE-2020-27153: bluez - In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() ro...
vendor_debian·2020·CVSS 8.6
CVE-2020-27153 [HIGH] CVE-2020-27153: bluez - In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() ro...
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
Scope: local
bookworm: resolved (fixed in 5.55-1)
bullseye: resolved (fixed in 5.55-1)
forky: resolved (fixed in 5.55-1)
sid: resolved (fixed in 5.55-1)
trixie: resolved (fixed in 5.55-1)
VulDB
BlueZ up to 5.54 MGMT Event shared/att.c disconnect_cb double free
vuldb·2026-04-16·CVSS 8.6
CVE-2020-27153 [HIGH] BlueZ up to 5.54 MGMT Event shared/att.c disconnect_cb double free
A vulnerability, which was classified as problematic, was found in BlueZ up to 5.54. This impacts the function disconnect_cb of the file shared/att.c of the component MGMT Event Handler. Such manipulation leads to double free.
This vulnerability is referenced as CVE-2020-27153. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
GHSA
GHSA-hrr3-cwf8-mjp6: In BlueZ before 5
ghsa_unreviewed·2022-05-24
CVE-2020-27153 [HIGH] CWE-415 GHSA-hrr3-cwf8-mjp6: In BlueZ before 5
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
OSV
bluez vulnerabilities
osv·2021-06-16·CVSS 4.2
CVE-2020-26558 [MEDIUM] bluez vulnerabilities
bluez vulnerabilities
It was discovered that BlueZ incorrectly checked certain permissions when
pairing. A local attacker could possibly use this issue to impersonate
devices. (CVE-2020-26558)
Jay LV discovered that BlueZ incorrectly handled redundant disconnect MGMT
events. A local attacker could use this issue to cause BlueZ to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-27153)
Ziming Zhang discovered that BlueZ incorrectly handled certain array
indexes. A local attacker could use this issue to cause BlueZ to crash,
resulting in a denial of service, or possibly obtain sensitive information.
This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2021-3588)
OSV
bluez vulnerabilities
osv·2021-06-16·CVSS 4.2
CVE-2020-26558 [MEDIUM] bluez vulnerabilities
bluez vulnerabilities
USN-4989-1 fixed several vulnerabilities in BlueZ. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that BlueZ incorrectly checked certain permissions when
pairing. A local attacker could possibly use this issue to impersonate
devices. (CVE-2020-26558)
Jay LV discovered that BlueZ incorrectly handled redundant disconnect MGMT
events. A local attacker could use this issue to cause BlueZ to crash,
resulting in a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-27153)
OSV
CVE-2020-27153: In BlueZ before 5
osv·2020-10-15·CVSS 8.6
CVE-2020-27153 [HIGH] CVE-2020-27153: In BlueZ before 5
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00036.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1884817https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721ahttps://github.com/bluez/bluez/commit/5a180f2ec9edfacafd95e5fed20d36fe8e077f07https://lists.debian.org/debian-lts-announce/2020/10/msg00022.htmlhttps://security.gentoo.org/glsa/202011-01https://www.debian.org/security/2021/dsa-4951http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00036.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1884817https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721ahttps://github.com/bluez/bluez/commit/5a180f2ec9edfacafd95e5fed20d36fe8e077f07https://lists.debian.org/debian-lts-announce/2020/10/msg00022.htmlhttps://security.gentoo.org/glsa/202011-01https://www.debian.org/security/2021/dsa-4951
2020-10-15
Published