<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix?]]></title><description><![CDATA[<p dir="auto">Here's some news link:</p>
<p dir="auto"><a href="https://arstechnica.com/information-technology/2017/09/bluetooth-bugs-open-billions-of-devices-to-attacks-no-clicking-required/" target="_blank" rel="noopener noreferrer nofollow ugc">https://arstechnica.com/information-technology/2017/09/bluetooth-bugs-open-billions-of-devices-to-attacks-no-clicking-required/</a></p>
<p dir="auto">Ubuntu CVE pages:</p>
<p dir="auto"><a href="https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000251.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000251.html</a></p>
<p dir="auto"><a href="https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000250.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000250.html</a></p>
]]></description><link>https://forums.ubports.com/topic/548/security-solved-can-we-get-blueborne-bluetooth-vulnerabilities-fixed-in-ota-2-or-ota-1-hotfix</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 07:01:09 GMT</lastBuildDate><atom:link href="https://forums.ubports.com/topic/548.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 Sep 2017 18:52:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Thu, 16 Nov 2017 18:53:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/talkless" aria-label="Profile: Talkless">@<bdi>Talkless</bdi></a> Had forgotten mine are now  on RC channel not stable and updated to r14 yesterday. Or am I getting mixed up with things and OTA's.</p>
]]></description><link>https://forums.ubports.com/post/5439</link><guid isPermaLink="true">https://forums.ubports.com/post/5439</guid><dc:creator><![CDATA[Lakotaubp]]></dc:creator><pubDate>Thu, 16 Nov 2017 18:53:39 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Thu, 16 Nov 2017 17:50:12 GMT]]></title><description><![CDATA[<p dir="auto">@Lakota said in <a href="/post/5437">[security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/talkless" aria-label="Profile: Talkless">@<bdi>Talkless</bdi></a> Thanks for clearing that up. Wasn't sure only read your comments after yesterday OT A's.</p>
</blockquote>
<p dir="auto">Uhm, what do you mean "after yesterday OT A's" ?</p>
<p dir="auto">It will be fixed on OTA-3, if I understood correctly, which is not yet released AFAIK.</p>
]]></description><link>https://forums.ubports.com/post/5438</link><guid isPermaLink="true">https://forums.ubports.com/post/5438</guid><dc:creator><![CDATA[Talkless]]></dc:creator><pubDate>Thu, 16 Nov 2017 17:50:12 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Thu, 16 Nov 2017 17:32:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/talkless" aria-label="Profile: Talkless">@<bdi>Talkless</bdi></a> Thanks for clearing that up. Wasn't sure only read your comments after yesterday OT A's.</p>
]]></description><link>https://forums.ubports.com/post/5437</link><guid isPermaLink="true">https://forums.ubports.com/post/5437</guid><dc:creator><![CDATA[Lakotaubp]]></dc:creator><pubDate>Thu, 16 Nov 2017 17:32:44 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Thu, 16 Nov 2017 16:58:22 GMT]]></title><description><![CDATA[<p dir="auto">@Lakota said in <a href="/post/5418">[security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/talkless" aria-label="Profile: Talkless">@<bdi>Talkless</bdi></a> Are they todays OTA's or future ones. Thanks</p>
</blockquote>
<p dir="auto">"next OTA", the future one.</p>
]]></description><link>https://forums.ubports.com/post/5436</link><guid isPermaLink="true">https://forums.ubports.com/post/5436</guid><dc:creator><![CDATA[Talkless]]></dc:creator><pubDate>Thu, 16 Nov 2017 16:58:22 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Wed, 15 Nov 2017 19:08:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/talkless" aria-label="Profile: Talkless">@<bdi>Talkless</bdi></a> Are they todays OTA's or future ones. Thanks</p>
]]></description><link>https://forums.ubports.com/post/5418</link><guid isPermaLink="true">https://forums.ubports.com/post/5418</guid><dc:creator><![CDATA[Lakotaubp]]></dc:creator><pubDate>Wed, 15 Nov 2017 19:08:40 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Wed, 15 Nov 2017 18:15:14 GMT]]></title><description><![CDATA[<p dir="auto">From <a href="https://ubports.com/blog/community-updates-5/post/community-update-15-98" target="_blank" rel="noopener noreferrer nofollow ugc">Community Update 15</a>:</p>
<blockquote>
<p dir="auto">People have been asking about the KRACK and BlueBorne vulnerabilities lately, and for good reason. These are highly public explots. Both have been fixed in the RC and Devel channels, with the fixes landing in Stable with the next OTA.</p>
</blockquote>
]]></description><link>https://forums.ubports.com/post/5411</link><guid isPermaLink="true">https://forums.ubports.com/post/5411</guid><dc:creator><![CDATA[Talkless]]></dc:creator><pubDate>Wed, 15 Nov 2017 18:15:14 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Wed, 04 Oct 2017 19:05:38 GMT]]></title><description><![CDATA[<p dir="auto">This issue has already been fixed in the hammerhead kernel via <a href="https://github.com/ubports/android_kernel_lge_hammerhead/commit/f0b4fb52922d612bbf2696eeae9fad41bb3d1f16" target="_blank" rel="noopener noreferrer nofollow ugc">this commit</a>. I believe a pull from the upstream Fairphone kernel fixed it, too, but I'll need to get confirmation.</p>
<p dir="auto">This fix has not been released to anything but the devel channel.</p>
]]></description><link>https://forums.ubports.com/post/4696</link><guid isPermaLink="true">https://forums.ubports.com/post/4696</guid><dc:creator><![CDATA[UniSuperBox]]></dc:creator><pubDate>Wed, 04 Oct 2017 19:05:38 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Wed, 04 Oct 2017 04:20:17 GMT]]></title><description><![CDATA[<p dir="auto">Ok, I've studied the CVE and the patches, and I'm pretty sure I can get this applied for the kernel source net/bluetooth/l2cap_core.c, at least on hammerhead.  I can take a similar look if somebody can tell me how to check out the source which includes src/sdpd-request.c.</p>
]]></description><link>https://forums.ubports.com/post/4687</link><guid isPermaLink="true">https://forums.ubports.com/post/4687</guid><dc:creator><![CDATA[vandys]]></dc:creator><pubDate>Wed, 04 Oct 2017 04:20:17 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Wed, 27 Sep 2017 18:28:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/flohack" aria-label="Profile: Flohack">@<bdi>Flohack</bdi></a> FYI, probably just got attacked at the local Cafe.  Turned on BT for my external keyboard, but keyboard typing was locked up, then an authentication dialog box popped up.  I shut the device down ASAP, will do a clean install since God knows what got scribbled.</p>
<p dir="auto">No BT in public for me until this is fixed!</p>
]]></description><link>https://forums.ubports.com/post/4524</link><guid isPermaLink="true">https://forums.ubports.com/post/4524</guid><dc:creator><![CDATA[vandys]]></dc:creator><pubDate>Wed, 27 Sep 2017 18:28:10 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Thu, 14 Sep 2017 20:10:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/flohack" aria-label="Profile: Flohack">@<bdi>Flohack</bdi></a> I am with you,on the not delaying part,I am near retirement,I want to see you guys take over the world before ~~~~~</p>
]]></description><link>https://forums.ubports.com/post/4098</link><guid isPermaLink="true">https://forums.ubports.com/post/4098</guid><dc:creator><![CDATA[Marathon2422]]></dc:creator><pubDate>Thu, 14 Sep 2017 20:10:23 GMT</pubDate></item><item><title><![CDATA[Reply to [security][solved] Can we get BlueBorne (Bluetooth vulnerabilities) fixed in OTA-2 or OTA-1 hotfix? on Thu, 14 Sep 2017 16:11:03 GMT]]></title><description><![CDATA[<p dir="auto">To be honest: We cannot do this so fast. We are a small team, and the patches we are talking here about need to be backported probably, which creates chance to introduce new errors, or in worst case new security flaws. The CVE 250 is fixed in Bluez, which means we could try to upgrade to a newer version in the same moment.</p>
<p dir="auto">The CVE 251 is a kernel patch, which is really painful, we would need to backport it to various 3.x kernel versions, which are all more or less end of life already. maybe someone can take a look if Android is backporting this for the older devices.</p>
<p dir="auto">Until we want to delay OTA-2 further to an unknown date I suggest releasing it without these patches, and make a hotfix later.</p>
<p dir="auto">BR</p>
]]></description><link>https://forums.ubports.com/post/4095</link><guid isPermaLink="true">https://forums.ubports.com/post/4095</guid><dc:creator><![CDATA[flohack]]></dc:creator><pubDate>Thu, 14 Sep 2017 16:11:03 GMT</pubDate></item></channel></rss>