CVE-2020-0556
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-0556 is a security vulnerability discovered in BlueZ, affecting versions before 5.54. The vulnerability was disclosed on March 12, 2020, and involves improper access control in the BlueZ subsystem. The issue affects multiple Linux distributions including Ubuntu, Debian, and OpenSUSE that utilize the BlueZ Bluetooth protocol stack (NVD, Ubuntu Security).

Technical details

The vulnerability stems from improper access control in BlueZ's HID (Human Interface Device) and HOGP (HID over GATT Profile) implementations, which did not specifically require bonding between the device and the host. The severity is rated as HIGH with a CVSS v3.1 base score of 7.1 (AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L). The vulnerability requires adjacent access for exploitation (NVD, Debian Security).

Impact

The vulnerability allows an unauthenticated user with adjacent access to potentially enable escalation of privilege and cause denial of service. Malicious devices can connect to a target host and impersonate an existing HID device without security, or cause SDP or GATT service discovery to take place, allowing HID reports to be injected to the input subsystem from a non-bonded source (Debian LTS, Gentoo Security).

Exploitability

The vulnerability requires adjacent access for exploitation, meaning an attacker needs to be within Bluetooth range of the target device. No authentication is required to exploit this vulnerability, making it relatively straightforward to exploit for attackers within range (NVD).

Mitigation and workarounds

The vulnerability was fixed in BlueZ version 5.54 by introducing a new configuration option called 'ClassicBondedOnly' for the HID profile. This option ensures that input connections only come from bonded device connections. The option defaults to 'false' to maximize device compatibility. Users are recommended to upgrade their BlueZ packages to version 5.54 or later (Debian Security, Gentoo Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management