Skip to content

Commit f14e024

Browse files
d3zd3zioannisg
authored andcommitted
doc: releases: Add CVE-2019-9506 to release notes
Add section about security vulnerability issues in the 2.0.0 release notes. Signed-off-by: David Brown <[email protected]>
1 parent ee57741 commit f14e024

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

doc/releases/release-notes-2.0.rst

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,19 @@ Major enhancements with this release include:
2323

2424
The following sections provide detailed lists of changes by component.
2525

26+
Security Vulnerability Related
27+
******************************
28+
29+
The following security vulnerability (CVE) was addressed in this
30+
release:
31+
32+
* Fixes CVE-2019-9506: The Bluetooth BR/EDR specification up to and
33+
including version 5.1 permits sufficiently low encryption key length
34+
and does not prevent an attacker from influencing the key length
35+
negotiation. This allows practical brute-force attacks (aka "KNOB")
36+
that can decrypt traffic and inject arbitrary ciphertext without the
37+
victim noticing.
38+
2639
Kernel
2740
******
2841

0 commit comments

Comments
 (0)