Bug 29248

Summary: bluez new security issue CVE-2021-0129
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: nicolas.salguero
Version: 8   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: bluez-5.55-3.1.mga8.src.rpm CVE:
Status comment: Patch available from Debian and upstream

Description David Walser 2021-07-12 17:13:21 CEST
Debian-LTS has issued an advisory on June 26:
https://www.debian.org/lts/security/2021/dla-2692
David Walser 2021-07-12 17:13:38 CEST

Status comment: (none) => Patch available from Debian and upstream
CC: (none) => nicolas.salguero

Comment 1 David Walser 2021-07-13 03:39:16 CEST
openSUSE has issued an advisory for this today (July 12):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FGEHNTYN7DOZBN7IPNNCVSIU2JNPC226/
Comment 2 Lewis Smith 2021-07-13 10:11:19 CEST
This SRPM has no registered maintainer, and has been committed by various people; so assigning this bug globally.

Assignee: bugsquad => pkg-bugs

Comment 3 Nicolas Salguero 2021-07-19 11:28:43 CEST
Hi,

After checking, it appears CVE-2021-0129 is another name for CVE-2020-26558, which was fixed in bug 29140.

Best regards,

Nico.
Comment 4 David Walser 2021-07-19 14:03:19 CEST
No, they're not the same issue, but apparently they were fixed in the same commit.  Thanks.
Comment 5 David Walser 2021-07-19 14:04:04 CEST
Closing.

*** This bug has been marked as a duplicate of bug 29140 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED