BlueZ Key Theft / bluetoothd Double-Free
Posted by deepcore on April 20, 2022 – 2:11 am
BlueZ suffers from a vulnerability where a malicious USB device can steal Bluetooth link keys over HCI using a fake BD_ADDR. It was also discovered that bluetoothd suffers from a double-free memory corruption flaw.
Post a reply
You must be logged in to post a comment.