Related Vulnerabilities: CVE-2020-26556  

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.

Severity Medium

Remote Yes

Type Private key recovery

Description

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.

AVG-1881 linux-hardened 5.12.6.hardened1-1 Medium Vulnerable

AVG-1880 linux-zen 5.12.6.zen1-1 Medium Vulnerable

AVG-1879 linux 5.12.6.arch4-1 Medium Vulnerable

AVG-1741 linux-lts 5.10.40-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1960012
https://kb.cert.org/vuls/id/799380
https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/