Fedora 40 : bluez / iwd / libell (2024-223428e702)

high Nessus Plugin ID 206950

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 40 host has packages installed that are affected by a vulnerability as referenced in the FEDORA-2024-223428e702 advisory.

libell 0.69:

Add support for getting remaining microseconds left on a timer.
Add support for setting link MTU on a network interface.

iwd 2.21:

Fix issue with pending scan requests after regdom update.
Fix issue with handling the rearming of the roaming timeout.
Fix issue with survey request and externally triggered scans.
Fix issue with RSSI fallback when setting CQM threshold fails.
Fix issue with FT-over-Air without offchannel support.
Add support for per station Affinities property.

bluez 5.78:

Fix issue with handling notification of scanned BISes to BASS Fix issue with handling checking BIS caps against peer caps.
Fix issue with handling MGMT Set Device Flags overwrites.
Fix issue with handling ASE notification order.
Fix issue with handling BIG Info report events.
Fix issue with handling PACS Server role.
Fix issue with registering UHID_START multiple times.
Fix issue with pairing method not setting auto-connect.


Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected bluez, iwd and / or libell packages.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2024-223428e702

Plugin Details

Severity: High

ID: 206950

File Name: fedora_2024-223428e702.nasl

Version: 1.1

Type: local

Agent: unix

Published: 9/11/2024

Updated: 9/11/2024

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2023-52424

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:40, p-cpe:/a:fedoraproject:fedora:iwd, p-cpe:/a:fedoraproject:fedora:libell, p-cpe:/a:fedoraproject:fedora:bluez

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/9/2024

Vulnerability Publication Date: 5/17/2024

Reference Information

CVE: CVE-2023-52424