CVE-2022-0204
published 2022-03-10CVE-2022-0204: A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an…
PriorityP348high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
1.81%
76.1th percentile
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | < 5.63 | 5.63 |
| bluez | bluez | — | — |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u2 | 5.55-3.1+deb11u2 |
| bluez | bluez | >= 0 < 5.64-1 | 5.64-1 |
| bluez | bluez | >= 0 < 5.64-1 | 5.64-1 |
| bluez | bluez | >= 0 < 5.64-1 | 5.64-1 |
| bluez | bluez | >= 0 < 5.48-0ubuntu3.8 | 5.48-0ubuntu3.8 |
| bluez | bluez | >= 0 < 5.53-0ubuntu3.5 | 5.53-0ubuntu3.5 |
| bluez | bluez | >= 0 < 5.37-0ubuntu5.3+esm2 | 5.37-0ubuntu5.3+esm2 |
| debian | bluez | < bluez 5.64-1 (bookworm) | bluez 5.64-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
BlueZ vulnerability
vendor_ubuntu·2022-02-08·CVSS 8.8
CVE-2022-0204 [HIGH] BlueZ vulnerability
Title: BlueZ vulnerability
Summary: BlueZ could be made to crash or run programs if it received
specially crafted network traffic.
Ziming Zhang discovered that BlueZ incorrectly handled memory write operations
in its gatt server. A remote attacker could possibly use this to cause BlueZ to
crash leading to a denial of service, or potentially remotely execute code.
(CVE-2022-0204)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-0204: bluez - A heap overflow vulnerability was found in bluez in versions prior to 5.63. An a...
vendor_debian·2022·CVSS 8.8
CVE-2022-0204 [HIGH] CVE-2022-0204: bluez - A heap overflow vulnerability was found in bluez in versions prior to 5.63. An a...
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 5.64-1)
bullseye: resolved (fixed in 5.55-3.1+deb11u2)
forky: resolved (fixed in 5.64-1)
sid: resolved (fixed in 5.64-1)
trixie: resolved (fixed in 5.64-1)
Red Hat
bluez: heap-based buffer overflow in the implementation of the gatt protocol
vendor_redhat·2021-11-12·CVSS 8.8
CVE-2022-0204 [HIGH] CWE-190 bluez: heap-based buffer overflow in the implementation of the gatt protocol
bluez: heap-based buffer overflow in the implementation of the gatt protocol
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
A heap overflow vulnerability was found in bluez. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
Package: bluez (Red Hat Enterprise Linux 6) - Not affected
Package: bluez (Red Hat Enterprise Linux 7) - Not affected
Package: bluez (Red Hat Enterprise Linux 8) - Not affected
Package: bluez (Red Hat Enterprise Linux 9) - Not affected
VulDB
BlueZ up to 5.62 Files heap-based overflow (GHSA-479m-xcq5-9g2q / EUVD-2022-15406)
vuldb·2026-04-16·CVSS 8.8
CVE-2022-0204 [HIGH] BlueZ up to 5.62 Files heap-based overflow (GHSA-479m-xcq5-9g2q / EUVD-2022-15406)
A vulnerability classified as critical has been found in BlueZ up to 5.62. This affects an unknown function of the component Files Handler. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is reported as CVE-2022-0204. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
GHSA-g2fr-rq52-c2h3: A heap overflow vulnerability was found in bluez in versions prior to 5
ghsa_unreviewed·2022-03-11
CVE-2022-0204 [HIGH] CWE-119 GHSA-g2fr-rq52-c2h3: A heap overflow vulnerability was found in bluez in versions prior to 5
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
OSV
CVE-2022-0204: A heap overflow vulnerability was found in bluez in versions prior to 5
osv·2022-03-10·CVSS 8.8
CVE-2022-0204 [HIGH] CVE-2022-0204: A heap overflow vulnerability was found in bluez in versions prior to 5
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
OSV
bluez vulnerability
osv·2022-02-08·CVSS 8.8
CVE-2022-0204 [HIGH] bluez vulnerability
bluez vulnerability
Ziming Zhang discovered that BlueZ incorrectly handled memory write operations
in its gatt server. A remote attacker could possibly use this to cause BlueZ to
crash leading to a denial of service, or potentially remotely execute code.
(CVE-2022-0204)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2039807https://github.com/bluez/bluez/commit/591c546c536b42bef696d027f64aa22434f8c3f0https://github.com/bluez/bluez/security/advisories/GHSA-479m-xcq5-9g2qhttps://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://security.gentoo.org/glsa/202209-16https://bugzilla.redhat.com/show_bug.cgi?id=2039807https://github.com/bluez/bluez/commit/591c546c536b42bef696d027f64aa22434f8c3f0https://github.com/bluez/bluez/security/advisories/GHSA-479m-xcq5-9g2qhttps://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlhttps://security.gentoo.org/glsa/202209-16
2022-03-10
Published