CVE-2020-26558

Related Vulnerabilities: CVE-2020-26558  

A vulnerability was found in Linux Kernel, where Passkey Entry protocol used in Secure Simple Pairing (SSP), Secure Connections (SC) and LE Secure Connections (LESC) of the Bluetooth Core Specification is vulnerable to an impersonation attack where an active attacker can impersonate the initiating device without any previous knowledge.

Description

A vulnerability was found in Linux Kernel, where Passkey Entry protocol used in Secure Simple Pairing (SSP), Secure Connections (SC) and LE Secure Connections (LESC) of the Bluetooth Core Specification is vulnerable to an impersonation attack where an active attacker can impersonate the initiating device without any previous knowledge.

Statement

Red Hat Product Security is aware of this issue. Updates will be released as they become available.

Red Hat Product Security is aware of this issue. Updates will be released as they become available.

Mitigation

Devices should not accept their own public key from a peer during a pairing session. The pairing procedure should be terminated with a failure status if this occurs.

Additional Information

  • Bugzilla 1918602: CVE-2020-26558 kernel: Passkey Entry protocol of the Bluetooth Core is vulnerable to an impersonation attack
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2020-26558