BleedingTooth: critical kernel Bluetooth vulnerability

Post Syndicated from original https://lwn.net/Articles/834297/rss

Several flaws in the BlueZ kernel Bluetooth stack prior to Linux 5.9 are being reported by Intel and by Google (GHSA-h637-c88j-47wq, GHSA-7mh3-gq28-gfrq, and GHSA-ccx2-w2r4-x649). They are collectively being called “BleedingTooth”, and more information will be forthcoming, though there is already a YouTube video demonstrating remote code execution using BleedingTooth.