CVE-2023-27349
Publication date 3 May 2024
Last updated 8 July 2025
Ubuntu priority
Cvss 3 Severity Score
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
Status
Package | Ubuntu Release | Status |
---|---|---|
bluez | 24.04 LTS noble |
Not affected
|
22.04 LTS jammy |
Fixed 5.64-0ubuntu1.3
|
|
20.04 LTS focal |
Fixed 5.53-0ubuntu3.8
|
|
18.04 LTS bionic |
Fixed 5.48-0ubuntu3.9+esm2
|
|
16.04 LTS xenial |
Fixed 5.37-0ubuntu5.3+esm4
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialSeverity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Adjacent |
Attack complexity | High |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-6809-1
- BlueZ vulnerabilities
- 5 June 2024