CVE-2021-3588 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
A security issue has been found in BlueZ before version 5.56. The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
Group Package Affected Fixed Severity Status Ticket
AVG-2061 bluez 5.55-3 5.56-1 Medium Fixed
References
https://github.com/bluez/bluez/issues/70
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?h=5.56&id=3a40bef49305f8327635b81ac8be52a3ca063d5a