CVE-2020-0556
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-0556 is a security vulnerability discovered in BlueZ, affecting versions before 5.54. The vulnerability was disclosed on March 12, 2020, and involves improper access control in the BlueZ subsystem. The issue affects multiple Linux distributions including Ubuntu, Debian, and OpenSUSE that utilize the BlueZ Bluetooth protocol stack (NVD, Ubuntu Security).

Technical details

The vulnerability stems from improper access control in BlueZ's HID (Human Interface Device) and HOGP (HID over GATT Profile) implementations, which did not specifically require bonding between the device and the host. The severity is rated as HIGH with a CVSS v3.1 base score of 7.1 (AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L). The vulnerability requires adjacent access for exploitation (NVD, Debian Security).

Impact

The vulnerability allows an unauthenticated user with adjacent access to potentially enable escalation of privilege and cause denial of service. Malicious devices can connect to a target host and impersonate an existing HID device without security, or cause SDP or GATT service discovery to take place, allowing HID reports to be injected to the input subsystem from a non-bonded source (Debian LTS, Gentoo Security).

Mitigation and workarounds

The vulnerability was fixed in BlueZ version 5.54 by introducing a new configuration option called 'ClassicBondedOnly' for the HID profile. This option ensures that input connections only come from bonded device connections. The option defaults to 'false' to maximize device compatibility. Users are recommended to upgrade their BlueZ packages to version 5.54 or later (Debian Security, Gentoo Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management