UbuntuUpdates.org

Package "bluez-cups"

Name: bluez-cups

Description:

Bluetooth printer driver for CUPS

Latest version: 5.64-0ubuntu1.5
Release: jammy (22.04)
Level: security
Repository: main
Head package: bluez
Homepage: http://www.bluez.org

Links


Download "bluez-cups"


Other versions of "bluez-cups" in Jammy

Repository Area Version
base main 5.64-0ubuntu1
updates main 5.64-0ubuntu1.4

Changelog

Version: 5.64-0ubuntu1.5 2026-10-09 00:07:32 UTC

bluez (5.64-0ubuntu1.5) jammy-security; urgency=medium

  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2026-19774.patch: a2dp: Fix handling of codec
      capability storage in profiles/audio/a2dp.c.
    - CVE-2026-19774
  * SECURITY UPDATE: out-of-bounds read
    - debian/patches/CVE-2026-75032_1.patch: avrcp: Fix Out-of-Bounds Read in
      AVRCP GetFolderItems parsing in profiles/audio/avrcp.c.
    - debian/patches/CVE-2026-75032_2.patch: avrcp: Fix media/folder name not
      being set in profiles/audio/avrcp.c.
    - CVE-2026-75032
  * SECURITY UPDATE: type confusion
    - debian/patches/CVE-2026-80185.patch: sdp-xml: Fix crash caused by type
      confusion when parsing crafted SDP XML in src/sdp-xml.c.
    - CVE-2026-80185
  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2026-80186.patch: eir: Fix stack buffer overflow when
      parsing the remote name in src/eir.c.
    - CVE-2026-80186
  * SECURITY UPDATE: out-of-bounds access
    - debian/patches/CVE-2026-85218.patch: avrcp: Fix out-of-bounds parsing of
      ListPlayerAttributes response in profiles/audio/avrcp.c.
    - CVE-2026-85218

 -- Allen Huang Wed, 07 Oct 2026 21:29:46 +0100

Source diff to previous version
CVE-2026-19774 BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary
CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile
CVE-2026-80185 BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SD
CVE-2026-80186 A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send

Version: 5.64-0ubuntu1.4 2025-01-22 17:07:02 UTC

  bluez (5.64-0ubuntu1.4) jammy-security; urgency=medium

  * SECURITY UPDATE: code exec via Phone Book Access Profile
    - debian/patches/CVE-2023-502xx.patch: fix not checking counter length
      in obexd/client/pbap.c.
    - CVE-2023-50229
    - CVE-2023-50230

 -- Marc Deslauriers <email address hidden> Tue, 21 Jan 2025 08:12:00 -0500

Source diff to previous version
CVE-2023-50229 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers
CVE-2023-50230 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers

Version: 5.64-0ubuntu1.3 2024-06-05 21:07:12 UTC

  bluez (5.64-0ubuntu1.3) jammy-security; urgency=medium

  * SECURITY UPDATE: null pointer dereference
    - debian/patches/CVE-2022-3563.patch: Fix null dereference in
      mgmt-tester.c.
    - CVE-2022-3563
  * SECURITY UPDATE: out-of-bounds write
    - debian/patches/CVE-2023-27349.patch: Fix crash while handling
      unsupported events in avrcp.c.
    - CVE-2023-27349

 -- Fabian Toepfer <email address hidden> Wed, 05 Jun 2024 12:10:29 +0200

Source diff to previous version
CVE-2022-3563 A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/
CVE-2023-27349 BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attacker

Version: 5.64-0ubuntu1.1 2023-12-07 04:06:55 UTC

  bluez (5.64-0ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: make conf compliant to HID specification
    - debian/patches/CVE-2023-45866.patch: input.conf: Change default of
      ClassicBondedOnly
    - CVE-2023-45866

 -- Nishit Majithia <email address hidden> Wed, 29 Nov 2023 17:01:28 +0530




About   -   Send Feedback to @ubuntu_updates