{"id":"MGASA-2023-0353","summary":"Updated bluez packages fix a security vulnerability","details":"This update fixes the following security issue.\nBluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral\nrole HID Device to initiate and establish an encrypted connection, and\naccept HID keyboard reports, potentially permitting injection of HID\nmessages when no user interaction has occurred in the Central role to\nauthorize such access (CVE-2023-45866).\n","modified":"2026-04-16T04:41:15.744525210Z","published":"2023-12-20T17:21:01Z","upstream":["CVE-2023-45866"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0353.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32604"},{"type":"WEB","url":"https://github.com/skysafe/reblog/tree/main/cve-2023-45866"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6540-1"},{"type":"WEB","url":"https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/profiles/input?id=25a471a83e02e1effb15d5a488b3f0085eaeb675"}],"affected":[{"package":{"name":"bluez","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/bluez?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.70-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0353.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}