In the free Bluetooth stack , which is used in Linux and Chrome OS distributions, vulnerability (), potentially allowing an attacker to gain access to the system. Due to improper access checks in the implementation of the HID and HOGP Bluetooth profiles, the vulnerability can enable denial of service or privilege escalation when connecting a malicious Bluetooth device without going through the device pairing procedure. A malicious Bluetooth device, without the pairing process, can impersonate another (keyboard, mouse, game controllers, etc.) or organize a covert data injection into the input subsystem.
According to For Intel, the issue appears in Bluez releases up to and including 5.52. It is unclear whether the issue affects release 5.53, which publicly, but has been available since February through and in . Patches fixing the vulnerability were proposed on March 10, while the release, was created on February 15. Updates in the distributions have not yet been formed ( ), , , , , ).
Source: opennet.ru
