Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1614159 - (CVE-2018-5383) CVE-2018-5383 kernel: Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange
CVE-2018-5383 kernel: Bluetooth implementations may not sufficiently validate...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20180723,repo...
: Security
Depends On: 1615683 1615684 1615685 1615686 1615689 1615706 1615707 1615687 1615688
Blocks: 1607700
  Show dependency treegraph
 
Reported: 2018-08-09 01:58 EDT by Sam Fowler
Modified: 2018-09-24 11:02 EDT (History)
40 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability in Bluetooth pairing potentially allows an attacker with physical proximity (within 30 meters) to gain unauthorized access via an adjacent network, intercept traffic and send forged pairing messages between two vulnerable Bluetooth devices. This may result in information disclosure, elevation of privilege and/or denial of service.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sam Fowler 2018-08-09 01:58:51 EDT
A vulnerability in Bluetooth pairing potentially allows an attacker with physical proximity (within 30 meters) to gain unauthorized access via an adjacent network, intercept traffic and send forged pairing messages between two vulnerable Bluetooth devices. This may result in information disclosure, elevation of privilege and/or denial of service.


External References:

https://www.kb.cert.org/vuls/id/304725
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00128.html
https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-update
Comment 2 Wade Mealing 2018-08-13 23:26:23 EDT
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1615683]
Comment 5 Wade Mealing 2018-08-14 01:32:33 EDT
Created linux-firmware tracking bugs for this issue:

Affects: fedora-all [bug 1615706]

Note You need to log in before you can comment on or make changes to this bug.