A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of all attributes that are requested are appended to the output buffer. There are no size checks whatsoever, resulting in a simple heap overflow if one can craft a request where the response is large enough to overflow the preallocated buffer. This issue exists in service_attr_req gets called by process_request (in sdpd-request.c), which also allocates the response buffer.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade bluez-debuginfoUpgrade bluez-hid2hciUpgrade bluez-libs-develUpgrade bluezUpgrade bluez-libsUpgrade bluez-cups | Oct 23, 2023 | Nov 29, 2021 |
| Debian | — | Upgrade bluez | Nov 29, 2021 | Nov 29, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bluez-libsUpgrade bluez | May 25, 2022 | Nov 29, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bluez-libsUpgrade bluez-libs-develUpgrade bluez | Mar 2, 2022 | Nov 29, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade bluez-help | Mar 3, 2022 | Nov 29, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 29, 2021 |
| Suse | — | Upgrade bluez-cupsUpgrade bluez-develUpgrade bluezUpgrade libbluetooth3 | Aug 9, 2024 | Nov 29, 2021 |
| Ubuntu | — | Upgrade libbluetooth3 (Ubuntu Pro)Upgrade libbluetooth3Upgrade bluez (Ubuntu Pro)Upgrade bluez | Mar 22, 2023 | Nov 29, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub