bluez: CVE-2021-3658

Related Vulnerabilities: CVE-2021-3658  

Debian Bug report logs - #991596
bluez: CVE-2021-3658

version graph

Reported by: Moritz Mühlenhoff <jmm@inutil.org>

Date: Wed, 28 Jul 2021 09:15:09 UTC

Severity: important

Tags: security, upstream

Found in version bluez/5.55-3.1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian Libvirt Maintainers <pkg-libvirt-maintainers@lists.alioth.debian.org>:
Bug#991596; Package src:libvirt. (Wed, 28 Jul 2021 09:15:10 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Mühlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian Libvirt Maintainers <pkg-libvirt-maintainers@lists.alioth.debian.org>. (Wed, 28 Jul 2021 09:15:10 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Mühlenhoff <jmm@inutil.org>
To: submit@bugs.debian.org
Subject: libvirt: CVE-2021-3658
Date: Wed, 28 Jul 2021 11:13:01 +0200
Source: libvirt
X-Debbugs-CC: team@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for libvirt.

CVE-2021-3658:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2021-3658  

Patch:
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055
	

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-3658
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3658

Please adjust the affected versions in the BTS as needed.



Bug reassigned from package 'src:libvirt' to 'bluez'. Request was from jmm@inutil.org (Moritz Muehlenhoff) to control@bugs.debian.org. (Wed, 28 Jul 2021 09:39:04 GMT) (full text, mbox, link).


Changed Bug title to 'bluez: CVE-2021-3658' from 'libvirt: CVE-2021-3658'. Request was from jmm@inutil.org (Moritz Muehlenhoff) to control@bugs.debian.org. (Wed, 28 Jul 2021 09:39:05 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian Bluetooth Maintainers <team+pkg-bluetooth@tracker.debian.org>:
Bug#991596; Package bluez. (Wed, 28 Jul 2021 12:33:03 GMT) (full text, mbox, link).


Acknowledgement sent to Guido Günther <agx@sigxcpu.org>:
Extra info received and forwarded to list. Copy sent to Debian Bluetooth Maintainers <team+pkg-bluetooth@tracker.debian.org>. (Wed, 28 Jul 2021 12:33:03 GMT) (full text, mbox, link).


Message #14 received at 991596@bugs.debian.org (full text, mbox, reply):

From: Guido Günther <agx@sigxcpu.org>
To: Moritz Mühlenhoff <jmm@inutil.org>, 991596@bugs.debian.org
Subject: Re: [Pkg-libvirt-maintainers] Bug#991596: libvirt: CVE-2021-3658
Date: Wed, 28 Jul 2021 14:31:06 +0200
control: reassign -1 bluez

Hi Moritz,
from the CVE and linked commit i think this should go to
bluez. Reassigning.
Cheers,
 -- Guido

On Wed, Jul 28, 2021 at 11:13:01AM +0200, Moritz Mühlenhoff wrote:
> Source: libvirt
> X-Debbugs-CC: team@security.debian.org
> Severity: important
> Tags: security
> 
> Hi,
> 
> The following vulnerability was published for libvirt.
> 
> CVE-2021-3658:
> https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2021-3658  
> 
> Patch:
> https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055
> 	
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> For further information see:
> 
> [0] https://security-tracker.debian.org/tracker/CVE-2021-3658
>     https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3658
> 
> Please adjust the affected versions in the BTS as needed.
> 
> _______________________________________________
> Pkg-libvirt-maintainers mailing list
> Pkg-libvirt-maintainers@alioth-lists.debian.net
> https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-libvirt-maintainers
> 



Added tag(s) upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 28 Jul 2021 14:42:10 GMT) (full text, mbox, link).


Marked as found in versions bluez/5.55-3.1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 28 Jul 2021 14:42:10 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jul 28 16:17:12 2021; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.