CVE-2021-3658
published 2022-03-02CVE-2021-3658: bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered…
PriorityP430medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
0.80%
52.3th percentile
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | < 5.61 | 5.61 |
| bluez | bluez | — | — |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u2 | 5.55-3.1+deb11u2 |
| bluez | bluez | >= 0 < 5.61-1 | 5.61-1 |
| bluez | bluez | >= 0 < 5.61-1 | 5.61-1 |
| bluez | bluez | >= 0 < 5.61-1 | 5.61-1 |
| bluez | bluez | >= 0 < 5.48-0ubuntu3.6 | 5.48-0ubuntu3.6 |
| bluez | bluez | >= 0 < 5.53-0ubuntu3.4 | 5.53-0ubuntu3.4 |
| debian | bluez | < bluez 5.61-1 (bookworm) | bluez 5.61-1 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net:sfc: fix non-freed irq in legacy irq mode
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47283 [MEDIUM] CWE-772 kernel: net:sfc: fix non-freed irq in legacy irq mode
kernel: net:sfc: fix non-freed irq in legacy irq mode
In the Linux kernel, the following vulnerability has been resolved:
net:sfc: fix non-freed irq in legacy irq mode
SFC driver can be configured via modparam to work using MSI-X, MSI or
legacy IRQ interrupts. In the last one, the interrupt was not properly
released on module remove.
It was not freed because the flag irqs_hooked was not set during
initialization in the case of using legacy IRQ.
Example of (trimmed) trace during module remove without this fix:
remove_proc_entry: removing non-empty directory 'irq/125', leaking at least '0000:3b:00.1'
WARNING: CPU: 39 PID: 3658 at fs/proc/generic.c:715 remove_proc_entry+0x15c/0x170
...trimmed...
Call Trace:
unregister_irq_proc+0xe3/0x100
free_desc+0x29/0x70
irq_free_descs+0x47/0x70
mp_unmap_
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2021-11-23·CVSS 6.5
CVE-2021-3658 [MEDIUM] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: Several security issues were fixed in BlueZ.
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
Instructions: In gene
Red Hat
bluez: adapter incorrectly restores Discoverable state after powered down
vendor_redhat·2021-07-27·CVSS 6.5
CVE-2021-3658 [MEDIUM] CWE-863 bluez: adapter incorrectly restores Discoverable state after powered down
bluez: adapter incorrectly restores Discoverable state after powered down
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
Mitigation: If bluetooth is disabled or never powered on, this vulnerabilit
Debian
CVE-2021-3658: bluez - bluetoothd from bluez incorrectly saves adapters' Discoverable status when a dev...
vendor_debian·2021·CVSS 6.5
CVE-2021-3658 [MEDIUM] CVE-2021-3658: bluez - bluetoothd from bluez incorrectly saves adapters' Discoverable status when a dev...
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
Scope: local
bookworm: resolved (fixed in 5.61-1)
bullseye: resolved (fixed in 5.55-3.1+deb11u2)
forky: resolved (fixed in 5.61-1)
sid: resolved (fixed in 5.61-1)
trixie: resolved (fixed in 5.61-1)
VulDB
BlueZ bluetoothd authorization (Issue 89)
vuldb·2026-04-16·CVSS 6.5
CVE-2021-3658 [MEDIUM] BlueZ bluetoothd authorization (Issue 89)
A vulnerability marked as critical has been reported in BlueZ. Affected by this issue is some unknown functionality of the component bluetoothd. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2021-3658. It is feasible to perform the attack on the physical device. No exploit exists.
To fix this issue, it is recommended to deploy a patch.
GHSA
GHSA-839c-8x38-qf59: bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up
ghsa_unreviewed·2022-03-04
CVE-2021-3658 [MEDIUM] CWE-863 GHSA-839c-8x38-qf59: bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
OSV
CVE-2021-3658: bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up
osv·2022-03-02·CVSS 6.5
CVE-2021-3658 [MEDIUM] CVE-2021-3658: bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
OSV
bluez vulnerabilities
osv·2021-11-23·CVSS 6.5
CVE-2021-3658 [MEDIUM] bluez vulnerabilities
bluez vulnerabilities
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1984728https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055https://github.com/bluez/bluez/commit/b497b5942a8beb8f89ca1c359c54ad67ec843055https://gitlab.gnome.org/GNOME/gnome-bluetooth/-/issues/89https://security.netapp.com/advisory/ntap-20220407-0002/https://bugzilla.redhat.com/show_bug.cgi?id=1984728https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055https://github.com/bluez/bluez/commit/b497b5942a8beb8f89ca1c359c54ad67ec843055https://gitlab.gnome.org/GNOME/gnome-bluetooth/-/issues/89https://lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlhttps://security.netapp.com/advisory/ntap-20220407-0002/
2022-03-02
Published