PT-2020-1889 · Linux+5 · Bluez+5

Published

2020-03-10

·

Updated

2025-07-15

·

CVE-2020-0556

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions BlueZ versions prior to 5.54
Description The issue is related to improper access control in the BlueZ subsystem, which may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access. This vulnerability can be exploited by a remote attacker to gain access to confidential data, disrupt their integrity, and cause a denial of service. The vulnerability is associated with a lack of privilege management mechanisms in the BlueZ package, which is used in Linux and Chrome OS distributions. A malicious Bluetooth device can exploit this vulnerability to impersonate another HID device, such as a keyboard, mouse, or game controller, or to secretly inject data into the input subsystem.
Recommendations For BlueZ versions prior to 5.54, update to version 5.54 or later to resolve the issue. As a temporary workaround, consider restricting access to the Bluetooth subsystem to minimize the risk of exploitation. Avoid using the Bluetooth HID Hosts feature until the issue is resolved.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1487
ALT-PU-2020-1523
BDU:2020-01165
CESA-2020_4001
CESA-2020_4481
CVE-2020-0556
DLA-2240-1
DSA-4647-1
MGASA-2020-0152
OPENSUSE-SU-2020:0479-1
OPENSUSE-SU-2020:0872-1
OPENSUSE-SU-2020_0479-1
OPENSUSE-SU-2020_0872-1
OPENSUSE-SU-2024:10657-1
RHSA-2020:4001
RHSA-2020:4481
RHSA-2020_4001
RHSA-2020_4481
SUSE-SU-2020:0918-1
SUSE-SU-2020:3034-1
SUSE-SU-2020:3516-1
SUSE-SU-2020_0918-1
SUSE-SU-2020_3034-1
SUSE-SU-2020_3516-1
USN-4311-1

Affected Products

Alt Linux
Bluez
Centos
Red Hat
Suse
Ubuntu