Bug#1006406: BlueMirror mesh attacks - CVE-2020-26557, CVE-2020-26559, CVE-2020-26560

2022-02-24 Thread Ben Hutchings
Control: retitle -1 BlueMirror mesh attacks - CVE-2020-26556, CVE-2020-26557, CVE-2020-26559, CVE-2020-26560 On Fri, 2022-02-25 at 03:25 +0100, Ben Hutchings wrote: > CVE-2020-26556 was already fixed in 5.50-1.1, but I don't see any > mention of the other issues in either the Debian changelog or

Bug#1006406: BlueMirror mesh attacks - CVE-2020-26557, CVE-2020-26559, CVE-2020-26560

2022-02-24 Thread Ben Hutchings
Source: bluez Severity: important Tags: security upstream X-Debbugs-Cc: Debian Security Team Several of the BlueMirror attacks described at involve mesh provisioning, which seems to implemented entirely in Bluez user-space. CVE-2020-26556 was already fixed