ISOMAN

CVE

CVE-2019-9506

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

Severity
HIGH
CVSS
8.1
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.html
  3. http://seclists.org/fulldisclosure/2019/Aug/11
  4. http://seclists.org/fulldisclosure/2019/Aug/13
  5. http://seclists.org/fulldisclosure/2019/Aug/14
  6. http://seclists.org/fulldisclosure/2019/Aug/15
  7. http://www.cs.ox.ac.uk/publications/publication12404-abstract.html
  8. http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190828-01-knob-en
  9. https://access.redhat.com/errata/RHSA-2019:2975
  10. https://access.redhat.com/errata/RHSA-2019:3055
  11. https://access.redhat.com/errata/RHSA-2019:3076
  12. https://access.redhat.com/errata/RHSA-2019:3089
  13. https://access.redhat.com/errata/RHSA-2019:3165
  14. https://access.redhat.com/errata/RHSA-2019:3187
  15. https://access.redhat.com/errata/RHSA-2019:3217
  16. https://access.redhat.com/errata/RHSA-2019:3218
  17. https://access.redhat.com/errata/RHSA-2019:3220
  18. https://access.redhat.com/errata/RHSA-2019:3231
  19. https://access.redhat.com/errata/RHSA-2019:3309
  20. https://access.redhat.com/errata/RHSA-2019:3517