Remote Code Execution Flaw in BlueZ Bluetooth Stack
CVE-2020-27153
8.6HIGH
What is CVE-2020-27153?
In versions of the BlueZ Bluetooth stack prior to 5.55, a double free vulnerability exists within the gatttool disconnect callback routine. This flaw can be exploited by a remote attacker during the service discovery process through a redundant disconnect MGMT event, potentially leading to a denial of service or even arbitrary code execution. Users are advised to upgrade to the latest version to mitigate this risk.