Bugzilla – Bug 1104301
VUL-0: CVE-2018-5383: kernel-firmware: Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange
Last modified: 2019-07-11 06:38:06 UTC
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device. References: https://www.kb.cert.org/vuls/id/304725 https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-update http://www.cs.technion.ac.il/~biham/BT/
SUSE-SU-2019:0422-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1104301 CVE References: CVE-2018-5383 Sources used: SUSE Linux Enterprise Server 12-LTSS (src): kernel-firmware-20140807git-5.11.1
SUSE-SU-2019:0427-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1104301 CVE References: CVE-2018-5383 Sources used: SUSE Linux Enterprise Server 12-SP1-LTSS (src): kernel-firmware-20160516git-10.16.1
SUSE-SU-2019:0466-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1104301 CVE References: CVE-2018-5383 Sources used: SUSE OpenStack Cloud 7 (src): kernel-firmware-20170530-21.28.1 SUSE Linux Enterprise Server for SAP 12-SP2 (src): kernel-firmware-20170530-21.28.1 SUSE Linux Enterprise Server 12-SP3 (src): kernel-firmware-20170530-21.28.1 SUSE Linux Enterprise Server 12-SP2-LTSS (src): kernel-firmware-20170530-21.28.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): kernel-firmware-20170530-21.28.1 SUSE Linux Enterprise Desktop 12-SP3 (src): kernel-firmware-20170530-21.28.1 SUSE Enterprise Storage 4 (src): kernel-firmware-20170530-21.28.1 SUSE CaaS Platform ALL (src): kernel-firmware-20170530-21.28.1 SUSE CaaS Platform 3.0 (src): kernel-firmware-20170530-21.28.1
openSUSE-SU-2019:0275-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1104301 CVE References: CVE-2018-5383 Sources used: openSUSE Leap 42.3 (src): kernel-firmware-20170530-26.1
SUSE-SU-2019:0427-2: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1104301 CVE References: CVE-2018-5383 Sources used: SUSE Linux Enterprise Server for SAP 12-SP1 (src): kernel-firmware-20160516git-10.16.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done