Seems like the flag defaults to true since December 7 (Fedora 38) with bluez v5.70-4:
$ rpm -q --changelog bluez | grep CVE-2023-45866 -C1
* Thu Dec 07 2023 Peter Robinson <pbrobinson@fedoraproject.org> - 5.70-4
- Add mitigation for CVE-2023-45866