UbuntuUpdates.org

Package "bluez"

Name: bluez

Description:

Bluetooth tools and daemons

Latest version: 5.85-4ubuntu0.3
Release: resolute (26.04)
Level: updates
Repository: main
Homepage: http://www.bluez.org

Links


Download "bluez"


Other versions of "bluez" in Resolute

Repository Area Version
base main 5.85-4
base universe 5.85-4
security universe 5.85-4ubuntu0.3
security main 5.85-4ubuntu0.3
updates universe 5.85-4ubuntu0.3

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 5.85-4ubuntu0.3 2026-10-09 10:08:05 UTC

bluez (5.85-4ubuntu0.3) resolute-security; urgency=medium

  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2026-19774.patch: a2dp: Fix handling of codec
      capability storage in profiles/audio/a2dp.c.
    - CVE-2026-19774
  * SECURITY UPDATE: out-of-bounds read
    - debian/patches/CVE-2026-75032_1.patch: avrcp: Fix Out-of-Bounds Read in
      AVRCP GetFolderItems parsing in profiles/audio/avrcp.c.
    - debian/patches/CVE-2026-75032_2.patch: avrcp: Fix media/folder name not
      being set in profiles/audio/avrcp.c.
    - CVE-2026-75032
  * SECURITY UPDATE: type confusion
    - debian/patches/CVE-2026-80185.patch: sdp-xml: Fix crash caused by type
      confusion when parsing crafted SDP XML in src/sdp-xml.c.
    - CVE-2026-80185
  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2026-80186.patch: eir: Fix stack buffer overflow when
      parsing the remote name in src/eir.c.
    - CVE-2026-80186
  * SECURITY UPDATE: out-of-bounds access
    - debian/patches/CVE-2026-85218.patch: avrcp: Fix out-of-bounds parsing of
      ListPlayerAttributes response in profiles/audio/avrcp.c.
    - CVE-2026-85218

 -- Allen Huang Wed, 07 Oct 2026 21:28:40 +0100

Source diff to previous version
CVE-2026-19774 BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary
CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile
CVE-2026-80185 BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SD
CVE-2026-80186 A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send

Version: 5.85-4ubuntu0.2 2026-09-15 05:07:28 UTC

bluez (5.85-4ubuntu0.2) resolute; urgency=medium

  [ Balachandra Bhat ]
  * Add patches cherry-picked from upstream:
    - profile: Set L2CAP IMTU for OBEX profile listeners (LP: #2163625)
    - obexd: fix PBAP PullPhoneBook failure with ebook backend (LP: #2164618)
    - advertising: Fix sending extra bytes with MGMT_OP_ADD_EXT_ADV_DATA
      (LP: #2164626)
    - gatt-client: Fix use-after-free caused by reentrant client teardown
      (LP: #2164630)

 -- Daniel van Vugt Thu, 27 Aug 2026 18:03:09 +0800

Source diff to previous version
2163625 [SRU][Resolute] Set L2CAP IMTU for OBEX profile listeners to fix OPP Rx KPI
2164618 [SRU][Resolute] Fix PBAP PullPhoneBook failure with ebook backend
2164626 [SRU][Resolute] Fix sending extra bytes with MGMT_OP_ADD_EXT_ADV_DATA
2164630 [SRU][Resolute] Fix use-after-free caused by reentrant client teardown in GATT implementation

Version: 5.85-4ubuntu0.1 2026-07-08 04:09:45 UTC

  bluez (5.85-4ubuntu0.1) resolute; urgency=medium

  [ Balachandra Bhat ]
  * d/patches: fix GATT cache DB Hash not updated on service add (LP: #2156411)
  * d/control: update maintainer for Ubuntu
  * d/patches: fix AVRCP volume control broken when AVRCP connects before AVDTP (LP: #2156488)

 -- Daniel van Vugt <email address hidden> Mon, 22 Jun 2026 17:52:31 +0800

2156411 [SRU][Resolute] GATT cached db hash is not updating when adding services to existing connection
2156488 [SRU][Resolute] volume control broken when AVRCP connects before AVDTP due to uninitialised target volume



About   -   Send Feedback to @ubuntu_updates