Authentication Bypass The advisory has been revoked - it doesn't affect any version of package kernel-selftests-internal  (opens in a new tab)


Threat Intelligence

EPSS
2.39% (82nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS9-KERNELSELFTESTSINTERNAL-5892853
  • published26 Jul 2021
  • disclosed18 May 2020

Introduced: 18 May 2020

CVE-2020-10135  (opens in a new tab)
CWE-290  (opens in a new tab)

Amendment

The Centos security team deemed this advisory irrelevant for Centos:9.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-selftests-internal package and not the kernel-selftests-internal package as distributed by Centos.

Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.