Debian Package Tracker
Register | Log in
Subscribe

bluez

Bluetooth tools and daemons

Choose email to subscribe with

general
  • source: bluez (main)
  • version: 5.69-1
  • maintainer: Debian Bluetooth Maintainers (DMD)
  • uploaders: Nobuhiro Iwamatsu [DMD]
  • arch: all
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.50-1.2~deb10u2
  • o-o-sec: 5.50-1.2~deb10u3
  • o-o-bpo: 5.54-1~bpo10+1
  • oldstable: 5.55-3.1
  • stable: 5.66-1
  • testing: 5.69-1
  • unstable: 5.69-1
versioned links
  • 5.50-1.2~deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.50-1.2~deb10u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.54-1~bpo10+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.55-3.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.66-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.69-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • bluetooth (44 bugs: 0, 43, 1, 0)
  • bluez (115 bugs: 0, 105, 10, 0)
  • bluez-cups (1 bugs: 0, 1, 0, 0)
  • bluez-hcidump (1 bugs: 0, 1, 0, 0)
  • bluez-meshd
  • bluez-obexd (1 bugs: 0, 1, 0, 0)
  • bluez-source
  • bluez-test-scripts (1 bugs: 0, 1, 0, 0)
  • bluez-test-tools
  • libbluetooth-dev
  • libbluetooth3 (1 bugs: 0, 0, 1, 0)
action needed
A new upstream version is available: 5.70 high
A new upstream version 5.70 is available, you should consider packaging it.
Created: 2023-09-29 Last update: 2023-10-03 01:41
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2022-08-08 Last update: 2023-10-03 03:30
5 bugs tagged patch in the BTS normal
The BTS contains patches fixing 5 bugs, consider including or untagging them.
Created: 2023-09-13 Last update: 2023-10-03 03:00
lintian reports 6 warnings normal
Lintian reports 6 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-08-06 Last update: 2023-09-01 18:09
Multiarch hinter reports 3 issue(s) low
There are issues with the multiarch metadata for this package.
  • bluetooth could be marked Multi-Arch: foreign
  • bluez-source could be marked Multi-Arch: foreign
  • bluez-test-scripts could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2023-10-03 01:44
6 low-priority security issues in bullseye low

There are 6 open security issues in bullseye.

6 issues left for the package maintainer to handle:
  • CVE-2021-3658: (needs triaging) bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
  • CVE-2022-0204: (needs triaging) A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
  • CVE-2021-41229: (needs triaging) BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.
  • CVE-2021-43400: (needs triaging) An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
  • CVE-2022-39176: (needs triaging) BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.
  • CVE-2022-39177: (needs triaging) BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.

You can find information about how to handle these issues in the security team's documentation.

Created: 2022-07-04 Last update: 2023-09-06 04:30
debian/patches: 11 patches to forward upstream low

Among the 14 debian patches available in version 5.69-1 of the package, we noticed the following issues:

  • 11 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-09-01 12:53
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-12-17 Last update: 2023-09-01 12:55
news
[rss feed]
  • [2023-09-06] bluez 5.69-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-01] Accepted bluez 5.69-1 (source) into unstable (Nobuhiro Iwamatsu)
  • [2023-08-11] bluez 5.68-2 MIGRATED to testing (Debian testing watch)
  • [2023-08-06] Accepted bluez 5.68-2 (source) into unstable (Nobuhiro Iwamatsu)
  • [2023-08-05] Accepted bluez 5.68-1 (source) into unstable (Nobuhiro Iwamatsu)
  • [2022-11-23] bluez 5.66-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-23] bluez 5.66-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-18] Accepted bluez 5.66-1 (source) into unstable (Nobuhiro Iwamatsu)
  • [2022-10-24] Accepted bluez 5.50-1.2~deb10u3 (source) into oldstable (Sylvain Beucler)
  • [2022-08-08] bluez 5.65-1 MIGRATED to testing (Debian testing watch)
  • [2022-08-08] bluez 5.65-1 MIGRATED to testing (Debian testing watch)
  • [2022-08-03] Accepted bluez 5.65-1 (source) into unstable (Nobuhiro Iwamatsu)
  • [2022-04-27] bluez 5.64-2 MIGRATED to testing (Debian testing watch)
  • [2022-04-27] bluez 5.64-2 MIGRATED to testing (Debian testing watch)
  • [2022-04-22] Accepted bluez 5.64-2 (source) into unstable (Nobuhiro Iwamatsu)
  • [2022-04-12] bluez 5.64-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-06] Accepted bluez 5.64-1 (source) into unstable (Nobuhiro Iwamatsu)
  • [2022-01-03] bluez 5.62-2 MIGRATED to testing (Debian testing watch)
  • [2021-12-27] Accepted bluez 5.62-2 (source) into unstable (Nobuhiro Iwamatsu)
  • [2021-12-24] bluez 5.62-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-19] Accepted bluez 5.62-1 (source) into unstable (Nobuhiro Iwamatsu)
  • [2021-11-27] Accepted bluez 5.43-2+deb9u5 (source) into oldoldstable (Sylvain Beucler)
  • [2021-09-08] bluez 5.61-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-03] Accepted bluez 5.61-1 (source) into unstable (Nobuhiro Iwamatsu)
  • [2021-08-27] Accepted bluez 5.50-1.2~deb10u2 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2021-08-07] Accepted bluez 5.50-1.2~deb10u2 (source) into stable->embargoed, stable (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2021-07-28] Accepted bluez 5.60-1~exp0 (source) into experimental (Nobuhiro Iwamatsu)
  • [2021-07-28] Accepted bluez 5.58-1~exp0 (source) into experimental (Nobuhiro Iwamatsu)
  • [2021-06-26] Accepted bluez 5.43-2+deb9u4 (source all amd64) into oldstable (Thorsten Alteholz)
  • [2021-06-18] bluez 5.55-3.1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 202 210
  • RC: 0
  • I&N: 181 188
  • M&W: 20 21
  • F&P: 1
  • patch: 5
links
  • homepage
  • lintian (0, 6)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 5.68-0ubuntu1
  • 131 bugs (1 patch)
  • patches for 5.68-0ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing