<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:59:45 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:11154 — Moderate: bluez security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:11154</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bluez, AlmaLinux:8: bluez-cups, AlmaLinux:8: bluez-hid2hci, AlmaLinux:8: bluez-libs, AlmaLinux:8: bluez-libs-devel, AlmaLinux:8: bluez-obexd&lt;/p&gt;
&lt;p&gt;The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (AlmaLinux), and pcmcia configuration files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution (CVE-2023-45866)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bluez, AlmaLinux:8: bluez-cups, AlmaLinux:8: bluez-hid2hci, AlmaLinux:8: bluez-libs, AlmaLinux:8: bluez-libs-devel, AlmaLinux:8: bluez-obexd&lt;/p&gt;
&lt;p&gt;The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (AlmaLinux), and pcmcia configuration files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution (CVE-2023-45866)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:11154</guid>
    </item>
    <item>
      <title>bdu:2023-08562</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08562</link>
      <description>bdu:2023-08562</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08562</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-45866</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-45866</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bluez&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bluez&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-45866</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0995 — De multiples vulnérabilités ont été découvertes dans Google Android.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0995</link>
      <description>certfr-2023-avi-0995</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0995</guid>
    </item>
    <item>
      <title>EUVD-2026-259884</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259884</link>
      <description>EUVD-2026-259884</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259884</guid>
    </item>
    <item>
      <title>fkie_cve-2023-45866</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-45866</link>
      <description>&lt;p&gt;Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-45866</guid>
    </item>
    <item>
      <title>GHSA-qjcj-xg77-6c32</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qjcj-xg77-6c32</link>
      <description>&lt;p&gt;Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qjcj-xg77-6c32</guid>
    </item>
    <item>
      <title>gsd-2023-45866</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-45866</link>
      <description>gsd-2023-45866</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-45866</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-45866 — Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encr…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-45866</link>
      <description>msrc_CVE-2023-45866</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-45866</guid>
    </item>
    <item>
      <title>OESA-2023-1948 — bluez security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1948</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: bluez, openEuler:20.03-LTS-SP3: bluez, openEuler:20.03-LTS-SP4: bluez, openEuler:22.03-LTS: bluez, openEuler:22.03-LTS-SP1: bluez, openEuler:22.03-LTS-SP2: bluez&lt;/p&gt;
&lt;p&gt;This package provides all utilities for use in Bluetooth applications. The BLUETOOTH trademarks are owned by Bluetooth SIG, Inc., U.S.A.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.(CVE-2023-45866)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: bluez, openEuler:20.03-LTS-SP3: bluez, openEuler:20.03-LTS-SP4: bluez, openEuler:22.03-LTS: bluez, openEuler:22.03-LTS-SP1: bluez, openEuler:22.03-LTS-SP2: bluez&lt;/p&gt;
&lt;p&gt;This package provides all utilities for use in Bluetooth applications. The BLUETOOTH trademarks are owned by Bluetooth SIG, Inc., U.S.A.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.(CVE-2023-45866)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1948</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13507-1 — bluez-5.70-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13507-1</link>
      <description>&lt;p&gt;bluez-5.70-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bluez-5.70-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13507-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03269-1 — Security update for bluez</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03269-1</link>
      <description>&lt;p&gt;Security update for bluez&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bluez&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03269-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-45866</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45866</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: bluez, Ubuntu:Pro:18.04:LTS: bluez, Ubuntu:20.04:LTS: bluez, Ubuntu:22.04:LTS: bluez, Ubuntu:24.04:LTS: bluez&lt;/p&gt;
&lt;p&gt;Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: bluez, Ubuntu:Pro:18.04:LTS: bluez, Ubuntu:20.04:LTS: bluez, Ubuntu:22.04:LTS: bluez, Ubuntu:24.04:LTS: bluez&lt;/p&gt;
&lt;p&gt;Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45866</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3057 — Google Android: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3057</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Google Android ausnutzen, um seine Privilegien zu erhöhen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Google Android ausnutzen, um seine Privilegien zu erhöhen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3057</guid>
    </item>
  </channel>
</rss>
