|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2020-26557: bluez,kernel-source-rt,kernel-source,kernel-source-azure: Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED WONTFIX | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | jack, mhocko, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/377979/ | ||
| Whiteboard: | |||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Marcus Meissner
2023-09-12 08:37:35 UTC
Joey, could you state if our software is affected and all and which? Joey, any progress on this bug? Sorry for I missed this CVE against Mesh Profile. After read the IEEE paper "BlueMirror: Reflections on Bluetooth Pairing and Provisioning Protocols" and "Mesh Profile Bluetooth ® Specification Revision: v1.0". In the IEEE paper, this CVE-2020-26557 is M-A2 attack. I set this issue to WONFIX because the M-A2 attack is against Link Manager layer in chip, likes M-A3 attack (bsc#1215239/CVE-2020-26556 and bsc#1215242/CVE-2020-26559). Kernel is NOT aware the M-A2 attack which is in LM layer in chip. So I didn't see solution or workaround can be implemented in bluez. For remission, the mesh service already be disabled by default because boo#1151518. And bluez package has a warning document : /usr/share/doc/packages/bluez/README-mesh.SUSE The bluetooth-mesh dbus system config has been disabled due to security concerns. See https://bugzilla.opensuse.org/show_bug.cgi?id=1151518 for details. If you want to use this feature anyway, copy bluetooth-mesh.conf to /etc/dbus-1/systemd.d/ and org.bluez.mesh.service to /etc/dbus-1/system-services/, then reboot. If anyone has better idea, just reopen and put suggestion on bug. Thanks! |