Rewterz Threat Alert – Latest Emotet – IoCs
October 15, 2020Rewterz Threat Advisory – CVE-2020-3991 – VMware Horizon Client for Windows
October 16, 2020Rewterz Threat Alert – Latest Emotet – IoCs
October 15, 2020Rewterz Threat Advisory – CVE-2020-3991 – VMware Horizon Client for Windows
October 16, 2020Severity
High
Analysis Summary
Updates are available to mitigate a serious flaw Google found in the Linux Bluetooth stack. A high-severity flaw was found in the Bluetooth stack in the Linux kernel versions below Linux 5.9 that support BlueZ. Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. BlueZ is found on Linux-based IoT devices and is the official Linux Bluetooth stack. Potential security vulnerabilities in BlueZ may allow escalation of privilege or information disclosure.BlueZ is releasing Linux kernel fixes to address these potential vulnerabilities.
CVE-2020-12351 – Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
CVE-2020-12352 – Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
CVE-2020-24490 – Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Impact
- Escalation of Privilege
- Information Disclosure
- Denial of Service
Affected Vendors
Linux
Affected Products
All Linux kernel versions before 5.10 that support BlueZ.
Remediation
Intel recommends updating the Linux kernel to version 5.10 or later.
If a kernel upgrade is not possible, Intel recommends the following kernel fixes to address these issues:
- https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-1-luiz.dentz@gmail.com/
- https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-2-luiz.dentz@gmail.com/
- https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-3-luiz.dentz@gmail.com/
- https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-4-luiz.dentz@gmail.com/
- https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=a2ec905d1e160a33b2e210e45ad30445ef26ce0e