Thread (5 messages) flat view 5 messages, 3 authors, 2018-08-29

RE: BlueZ: How to avoid fixed Coordinate Invalid Curve Attack

From: NXP psirt <hidden>
Date: 2018-08-28 17:33:45

Hi Marcel,

Is this the patch you are referring to?

https://patchwork.kernel.org/patch/9976233/


If not can you kindly point us to the patch that has been accepted in the mainline to address this vulnerability.

Kind Regards

Asim

NXP PSIRT

-----Original Message-----
From: Marcel Holtmann <marcel@holtmann.org> 
Sent: Tuesday, August 28, 2018 4:56 AM
To: Andy Duan <redacted>
Cc: rtatiya@codeaurora.org; Luiz Augusto von Dentz <redacted>; Johan Hedberg <redacted>; Asim Zaidi <redacted>; linux-bluetooth@vger.kernel.org
Subject: Re: BlueZ: How to avoid fixed Coordinate Invalid Curve Attack

Hi Andy,
Do you have patches for BlueZ to avoid Bluetooth curve attack ?

As I know, Many vendors supply Android Flueride host fixes & Firmware fixes to avoid the curve attack, but BlueZ community doesn’t have the topic. Does there have plan to fix the hole ? 
the Linux kernel crypto subsystem and its ECDH support has a patch to ensure that the public key is validated before calculating the shared secret.

Regards

Marcel

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help