CVE-2019-8921
published 2021-11-29CVE-2019-8921: An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a…
PriorityP434medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
0.94%
57.1th percentile
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting in leaking arbitrary heap data. The root cause can be found in the function service_attr_req of sdpd-request.c. The server does not check whether the CSTATE data is the same in consecutive requests, and instead simply trusts that it is the same.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | <= 5.48 | — |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| bluez | bluez | >= 0 < 5.37-0ubuntu5.3+esm5 | 5.37-0ubuntu5.3+esm5 |
| debian | bluez | < bluez 5.54-1 (bookworm) | bluez 5.54-1 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
BlueZ up to 5.48 bluetoothd sdpd-request.c heap-based overflow (Nessus ID 216160)
vuldb·2026-04-16·CVSS 6.5
CVE-2019-8921 [MEDIUM] BlueZ up to 5.48 bluetoothd sdpd-request.c heap-based overflow (Nessus ID 216160)
A vulnerability was found in BlueZ up to 5.48 and classified as critical. This affects an unknown part of the file sdpd-request.c of the component bluetoothd. Such manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2019-8921. The attack needs to be initiated within the local network. No exploit is available.
OSV
bluez vulnerabilities
osv·2025-02-12·CVSS 6.5
CVE-2019-8921 [MEDIUM] bluez vulnerabilities
bluez vulnerabilities
Julian Rauchberger discovered that BlueZ did not correctly handle certain
memory operations. An attacker could possibly use this issue to leak
sensitive information or execute arbitrary code.
(CVE-2019-8921, CVE-2019-8922)
GHSA
GHSA-69h8-fh92-ch8q: An issue was discovered in bluetoothd in BlueZ through 5
ghsa_unreviewed·2021-11-30
CVE-2019-8921 [MEDIUM] CWE-345 GHSA-69h8-fh92-ch8q: An issue was discovered in bluetoothd in BlueZ through 5
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting in leaking arbitrary heap data. The root cause can be found in the function service_attr_req of sdpd-request.c. The server does not check whether the CSTATE data is the same in consecutive requests, and instead simply trusts that it is the same.
OSV
CVE-2019-8921: An issue was discovered in bluetoothd in BlueZ through 5
osv·2021-11-29·CVSS 6.5
CVE-2019-8921 [MEDIUM] CVE-2019-8921: An issue was discovered in bluetoothd in BlueZ through 5
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting in leaking arbitrary heap data. The root cause can be found in the function service_attr_req of sdpd-request.c. The server does not check whether the CSTATE data is the same in consecutive requests, and instead simply trusts that it is the same.
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2025-02-12·CVSS 6.5
CVE-2019-8921 [MEDIUM] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: BlueZ could be made to crash or run programs as your login if it received
specially crafted Bluetooth requests.
Julian Rauchberger discovered that BlueZ did not correctly handle certain
memory operations. An attacker could possibly use this issue to leak
sensitive information or execute arbitrary code.
(CVE-2019-8921, CVE-2019-8922)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bluez: information leak in service_attr_req() in sdpd-request.c via a crafted CSTATE
vendor_redhat·2019-02-25·CVSS 6.5
CVE-2019-8921 [MEDIUM] CWE-20 bluez: information leak in service_attr_req() in sdpd-request.c via a crafted CSTATE
bluez: information leak in service_attr_req() in sdpd-request.c via a crafted CSTATE
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting in leaking arbitrary heap data. The root cause can be found in the function service_attr_req of sdpd-request.c. The server does not check whether the CSTATE data is the same in consecutive requests, and instead simply trusts that it is the same.
An issue was discovered in bluetoothd in BlueZ through version 5.48. The vulnerability lies in the handling of buffered data where it is possible to cause the server to return more bytes
Debian
CVE-2019-8921: bluez - An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability l...
vendor_debian·2019·CVSS 6.5
CVE-2019-8921 [MEDIUM] CVE-2019-8921: bluez - An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability l...
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting in leaking arbitrary heap data. The root cause can be found in the function service_attr_req of sdpd-request.c. The server does not check whether the CSTATE data is the same in consecutive requests, and instead simply trusts that it is the same.
Scope: local
bookworm: resolved (fixed in 5.54-1)
bullseye: resolved (fixed in 5.54-1)
forky: resolved (fixed in 5.54-1)
sid: resolved (fixed in 5.54-1)
trixie: resolved (fixed in 5.54-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://security.netapp.com/advisory/ntap-20211203-0002/https://ssd-disclosure.com/ssd-advisory-linux-bluez-information-leak-and-heap-overflow/https://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://security.netapp.com/advisory/ntap-20211203-0002/https://ssd-disclosure.com/ssd-advisory-linux-bluez-information-leak-and-heap-overflow/
2021-11-29
Published