[CLSA-2026:1788176031] Fix CVE(s): CVE-2023-27349
Type:
security
Severity:
Important
Release date:
2026-08-31 11:34:02 UTC
Description:
* SECURITY UPDATE: out-of-bounds write via an unsupported AVRCP event - debian/patches/CVE-2023-27349.patch: reject an event id above AVRCP_EVENT_LAST in avrcp_handle_event() before it is used to index session->transaction_events, a 14-entry array (upstream f54299a850). - CVE-2023-27349
CVEs fixed:
Updated packages:
  • bluetooth_5.48-0ubuntu3.9+tuxcare.els1_all.deb
    sha:153a6885accd81f1f90da4fdae7dd1be0984e130
  • bluez_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
    sha:d7e567364e387965590ce8abc7d71c476e9b8742
  • bluez-cups_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
    sha:57cf19a2c2ba670e2f56a1505a9de583c2db63d0
  • bluez-hcidump_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
    sha:42a203a99b34a5378129923414e7e85b79770327
  • bluez-obexd_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
    sha:9dd6d8105988bf42639d2f6e6f7ab19aee47ef71
  • bluez-tests_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
    sha:75c13696320a13b82ae8015821704899b22ee972
  • libbluetooth-dev_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
    sha:5f29e3c1d3f1f5d96e10ada065be13b02579ec37
  • libbluetooth3_5.48-0ubuntu3.9+tuxcare.els1_amd64.deb
    sha:0fd07f0d085f514ad13c15b9975b512283c46fdc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.