Bug 30556

Summary: bluez new security issue(s) (lp#1977968)
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, davidwhodgins, nicolas.salguero, sysadmin-bugs, tarazed25
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: bluez-5.55-3.4.mga8.src.rpm CVE:
Status comment:

Description David Walser 2022-06-16 22:37:17 CEST
Ubuntu has issued an advisory on June 15:
https://ubuntu.com/security/notices/USN-5481-1

The issues are fixed upstream in 5.60.
Comment 1 Nicolas Salguero 2022-06-17 14:13:05 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities.

References:
https://ubuntu.com/security/notices/USN-5481-1
========================

Updated packages in core/updates_testing:
========================
bluez-5.55-3.5.mga8
bluez-cups-5.55-3.5.mga8
bluez-hid2hci-5.55-3.5.mga8
bluez-mesh-5.55-3.5.mga8
lib(64)bluez3-5.55-3.5.mga8
lib(64)bluez-devel-5.55-3.5.mga8

from SRPM:
bluez-5.55-3.5.mga8.src.rpm

Assignee: bugsquad => qa-bugs
CC: (none) => nicolas.salguero
Status: NEW => ASSIGNED

Comment 2 Len Lawrence 2022-06-17 20:56:14 CEST
mga8, x64

Updated cleanly.  Paired with a portable speaker.  It found my ancient Nokia but I have no idea of the PIN number.  Other devices were discovered as well like the Soundtouch sound bar and TV in another room, and BT adapters on other machines.

The old CUPS printer connection did not work so the bluetooth printer had to be removed and set up again - that was a case of following one's nose.  It seems to vary slightly every time.
First it needed to be connected to bluetooth - it was found OK.  Then it needed to be routed to a serial port /dev/rfcomm0, which worked.  Used the hardware section of MCC to find a driver for HP Officejet 100 Mobile then localhost:631 in firefox to name it and set the defaults.  Test page printed fine.

So, bluez is working fine on this machine.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => tarazed25

Comment 3 Thomas Andrews 2022-06-18 14:13:57 CEST
Validating. Advisory in Comment 1.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-06-18 21:16:07 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 4 Mageia Robot 2022-06-18 23:31:54 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0235.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED