Bug 2278787 (CVE-2023-27349) - CVE-2023-27349 BlueZ: Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
Summary: CVE-2023-27349 BlueZ: Audio Profile AVRCP Improper Validation of Array Index ...
Keywords:
Status: NEW
Alias: CVE-2023-27349
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2278862
TreeView+ depends on / blocked
 
Reported: 2024-05-03 04:47 UTC by TEJ RATHI
Modified: 2025-04-22 01:37 UTC (History)
0 users

Fixed In Version: bluez 5.67
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:9413 0 None None None 2024-11-12 10:45:20 UTC
Red Hat Product Errata RHSA-2025:4043 0 None None None 2025-04-22 01:37:01 UTC

Description TEJ RATHI 2024-05-03 04:47:08 UTC
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.

The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.

https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=f54299a850676d92c3dafd83e9174fcfe420ccc9
https://www.zerodayinitiative.com/advisories/ZDI-23-386/

Comment 2 errata-xmlrpc 2024-11-12 10:45:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:9413 https://access.redhat.com/errata/RHSA-2024:9413

Comment 3 errata-xmlrpc 2025-04-22 01:37:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:4043 https://access.redhat.com/errata/RHSA-2025:4043


Note You need to log in before you can comment on or make changes to this bug.