Back to bug 1960011

Who When What Removed Added
Guilherme de Almeida Suckevicz 2021-05-12 19:13:30 UTC CC security-response-team
Guilherme de Almeida Suckevicz 2021-05-12 19:18:49 UTC Summary EMBARGOED CVE-2020-26559 kernel: Authvalue Leak (Mesh ANSSI.4) EMBARGOED CVE-2020-26559 kernel: Authvalue leak in Bluetooth Mesh Provisioning
RaTasha Tillery-Smith 2021-05-13 17:53:48 UTC Doc Text A flaw was found in the Linux kernel’s Bluetooth Mesh Profile implementation. The Mesh Provisioning procedure has a vulnerability that allows an attacker that was provisioned without access to the AuthValue to identify the AuthValue directly, without brute-forcing its value. Even when a randomly generated AuthValue with a full 128-bits of entropy is used, an attacker acquiring the Provisioner’s public key, provisioning confirmation value, the random value, and providing its public key for use in the provisioning procedure can directly compute the AuthValue used. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Florencio Cano 2021-05-24 09:52:25 UTC CC bdettelb, tomckay
Rohit Keshri 2021-05-26 13:09:59 UTC Group security, qe_staff
CC adscvr, airlied, alciregi, bskeggs, hdegoede, jarodwilson, jeremy, jforbes, jglisse, jonathan, josef, jwboyer, kernel-maint, kernel-mgr, linville, masami256, mchehab, steved
Summary EMBARGOED CVE-2020-26559 kernel: Authvalue leak in Bluetooth Mesh Provisioning CVE-2020-26559 kernel: Authvalue leak in Bluetooth Mesh Provisioning
Petr Matousek 2021-05-26 15:45:24 UTC CC darcari, dzickus, gtiwari, hwkernel-mgr
Red Hat Bugzilla 2021-05-30 12:01:42 UTC CC blc
Red Hat Bugzilla 2021-05-30 12:34:23 UTC CC bhu
Jeff Fearn 🐞 2021-06-03 11:12:16 UTC CC blc
Jeff Fearn 🐞 2021-06-03 12:00:38 UTC CC bhu
Pedro Sampaio 2021-06-08 18:03:26 UTC Blocks 1969593
Rohit Keshri 2021-06-08 18:10:38 UTC Blocks 1904532
Rohit Keshri 2021-06-08 18:34:01 UTC Depends On 1969613, 1969614
Rohit Keshri 2021-06-08 18:35:27 UTC CC bnocera, dwmw2, spacewar
Rohit Keshri 2021-06-08 18:35:51 UTC Depends On 1969615
Red Hat Bugzilla 2021-09-15 05:47:22 UTC CC jglisse
Red Hat Bugzilla 2022-06-04 08:05:09 UTC CC fpacheco
Red Hat Bugzilla 2022-07-16 03:21:20 UTC CC brdeoliv
Red Hat Bugzilla 2022-12-26 18:52:40 UTC CC gtiwari
Red Hat Bugzilla 2022-12-31 23:36:55 UTC CC fhrbata
Red Hat Bugzilla 2023-04-01 08:42:51 UTC CC dhoward
Red Hat Bugzilla 2023-07-07 08:31:37 UTC CC security-response-team
Assignee security-response-team nobody

Back to bug 1960011