Release date:
2026-08-31 11:34:02 UTC
Description:
* SECURITY UPDATE: out-of-bounds write via an unsupported AVRCP event
- debian/patches/CVE-2023-27349.patch: reject an event id above
AVRCP_EVENT_LAST in avrcp_handle_event() before it is used to index
session->transaction_events, a 14-entry array (upstream f54299a850).
- CVE-2023-27349
Updated packages:
-
bluetooth_5.48-0ubuntu3.9+tuxcare.els1_all.deb
sha:153a6885accd81f1f90da4fdae7dd1be0984e130
-
bluez_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
sha:d7e567364e387965590ce8abc7d71c476e9b8742
-
bluez-cups_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
sha:57cf19a2c2ba670e2f56a1505a9de583c2db63d0
-
bluez-hcidump_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
sha:42a203a99b34a5378129923414e7e85b79770327
-
bluez-obexd_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
sha:9dd6d8105988bf42639d2f6e6f7ab19aee47ef71
-
bluez-tests_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
sha:75c13696320a13b82ae8015821704899b22ee972
-
libbluetooth-dev_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
sha:5f29e3c1d3f1f5d96e10ada065be13b02579ec37
-
libbluetooth3_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
sha:0fd07f0d085f514ad13c15b9975b512283c46fdc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.