| Summary: | bluez new security issue CVE-2021-3658 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, nicolas.salguero, sysadmin-bugs, tarazed25 |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | bluez-5.55-3.1.mga8.src.rpm | CVE: | CVE-2021-3658 |
| Status comment: | |||
|
Description
David Walser
2021-08-02 17:02:14 CEST
David Walser
2021-08-02 17:02:54 CEST
Whiteboard:
(none) =>
MGA8TOO Suggested advisory: ======================== The updated packages fix a security vulnerability: Adapter incorrectly restores Discoverable state after powered down. (CVE-2021-3658) References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3658 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TWHARMQLSFEQB4QZ3AQNN4HCL3HCRAVH/ ======================== Updated packages in core/updates_testing: ======================== bluez-hid2hci-5.55-3.2.mga8 bluez-cups-5.55-3.2.mga8 lib(64)bluez3-5.55-3.2.mga8 lib(64)bluez-devel-5.55-3.2.mga8 bluez-mesh-5.55-3.2.mga8 bluez-5.55-3.2.mga8 from SRPM: bluez-5.55-3.2.mga8.src.rpm Source RPM:
bluez-5.59-2.mga9.src.rpm =>
bluez-5.55-3.1.mga8.src.rpm Could not see the fault here before updating. $ rpm -q bluez bluez-5.55-3.1.mga8 Turned off bluetooth via the panel icon. $ bluetoothctl [bluetooth]# list Controller 00:02:72:C6:B6:63 canopus [default] <switched on bluetooth via panel> [CHG] Controller 00:02:72:C6:B6:63 Class: 0x001c0104 [CHG] Controller 00:02:72:C6:B6:63 Powered: yes [bluetooth]# list Controller 00:02:72:C6:B6:63 canopus [default] [bluetooth]# discoverable on Changing discoverable on succeeded [bluetooth]# power off Changing power off succeeded [CHG] Controller 00:02:72:C6:B6:63 Powered: no [CHG] Controller 00:02:72:C6:B6:63 Discovering: no [CHG] Controller 00:02:72:C6:B6:63 Class: 0x00000000 [bluetooth]# quit Switched bluetooth off. Bluetooth service still running. $ rfkill ID TYPE DEVICE SOFT HARD 0 bluetooth hci0 blocked unblocked Updated the packages. Bluetooth enabled automatically. All three audio devices listed as before. $ bluetoothctl Agent registered [bluetooth]# list Controller 00:02:72:C6:B6:63 canopus [default] <switched on bluetooth audio speaker> [CHG] Device 00:0C:8A:9D:21:C3 Connected: yes [Bose Mini SoundLink]# exit Connected to portable HP Officejet printer and sent a couple of pages from LibreOffice. Working fine here. CC:
(none) =>
tarazed25 installed and rebooted system working fine CC:
(none) =>
brtians1 Validating. Advisory in Comment 1. CC:
(none) =>
andrewsfarm, sysadmin-bugs
Thomas Backlund
2021-08-06 11:05:11 CEST
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0395.html Status:
ASSIGNED =>
RESOLVED |