Bug 1960011 (CVE-2020-26559) - CVE-2020-26559 kernel: Authvalue leak in Bluetooth Mesh Provisioning
Summary: CVE-2020-26559 kernel: Authvalue leak in Bluetooth Mesh Provisioning
Keywords:
Status: NEW
Alias: CVE-2020-26559
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 1969613 1969614 1969615
Blocks: 1969593
TreeView+ depends on / blocked
 
Reported: 2021-05-12 19:13 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-09-19 14:13 UTC (History)
43 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the Linux kernel’s Bluetooth Mesh Profile implementation. The Mesh Provisioning procedure has a vulnerability that allows an attacker that was provisioned without access to the AuthValue to identify the AuthValue directly, without brute-forcing its value. Even when a randomly generated AuthValue with a full 128-bits of entropy is used, an attacker acquiring the Provisioner’s public key, provisioning confirmation value, the random value, and providing its public key for use in the provisioning procedure can directly compute the AuthValue used. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2021-05-12 19:13:30 UTC
The Mesh Provisioning procedure described in the Bluetooth Mesh Profile Specification versions 1.0 and 1.0.1 could allow an attacker that was provisioned without access to the AuthValue to identify the AuthValue directly without brute-forcing its value. Even when a randomly generated AuthValue with a full 128-bits of entropy is used, an attacker acquiring the Provisioner’s public key, provisioning confirmation value, and provisioning random value and providing its public key for use in the provisioning procedure will be able to directly compute the AuthValue used.

Comment 12 Rohit Keshri 2021-06-08 18:35:58 UTC
Created bluez tracking bugs for this issue:

Affects: fedora-all [bug 1969615]


Note You need to log in before you can comment on or make changes to this bug.