PT-2023-9855 · Bluez+8 · Bluez+8

Lucas Leong

+1

·

Published

2023-04-26

·

Updated

2026-03-29

·

CVE-2023-50229

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BlueZ (affected versions not specified)
Description The issue is related to a heap-based buffer overflow in the Phone Book Access profile of BlueZ, which can be exploited by network-adjacent attackers to execute arbitrary code on affected installations. User interaction is required, as the target must connect to a malicious Bluetooth device. The flaw exists due to the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This allows an attacker to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:9413
AZL-40217
AZL-40267
BDU:2025-00968
CVE-2023-50229
DLA-3879-1
INFSA-2024_9413
OESA-2024-1029
OPENSUSE-SU-2024_0182-1
OPENSUSE-SU-2024_0183-1
OPENSUSE-SU-2024_0204-1
RHSA-2024:9413
RHSA-2024_9413
RLSA-2024:9413
SUSE-SU-2024:0166-1
SUSE-SU-2024:0167-1
SUSE-SU-2024:0182-1
SUSE-SU-2024:0183-1
SUSE-SU-2024:0204-1
SUSE-SU-2024_0182-1
SUSE-SU-2024_0183-1
SUSE-SU-2024_0204-1
USN-7222-1
ZDI-23-1811

Affected Products

Almalinux
Astra Linux
Bluez
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu