CVE-2021-41229
published 2021-11-12CVE-2021-41229: BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be…
PriorityP427medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
1.10%
62.1th percentile
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | — | — |
| bluez | bluez | — | — |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u2 | 5.55-3.1+deb11u2 |
| bluez | bluez | >= 0 < 5.62-2 | 5.62-2 |
| bluez | bluez | >= 0 < 5.62-2 | 5.62-2 |
| bluez | bluez | >= 0 < 5.62-2 | 5.62-2 |
| bluez | bluez | >= 0 < 5.48-0ubuntu3.6 | 5.48-0ubuntu3.6 |
| bluez | bluez | >= 0 < 5.53-0ubuntu3.4 | 5.53-0ubuntu3.4 |
| debian | bluez | < bluez 5.62-2 (bookworm) | bluez 5.62-2 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2021-11-23·CVSS 6.5
CVE-2021-3658 [MEDIUM] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: Several security issues were fixed in BlueZ.
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
Instructions: In gene
Red Hat
bluez: memory leak in the SDP protocol
vendor_redhat·2021-11-12·CVSS 4.3
CVE-2021-41229 [MEDIUM] CWE-400 bluez: memory leak in the SDP protocol
bluez: memory leak in the SDP protocol
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.
Package: bluez (Red Hat Enterprise Linux 6) - Out of support scope
Package: bluez (Red Hat Enterprise Linux 7) - Out of support scope
Package: bluez (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-41229: bluez - BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerabil...
vendor_debian·2021·CVSS 4.3
CVE-2021-41229 [MEDIUM] CVE-2021-41229: bluez - BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerabil...
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.
Scope: local
bookworm: resolved (fixed in 5.62-2)
bullseye: resolved (fixed in 5.55-3.1+deb11u2)
forky: resolved (fixed in 5.62-2)
sid: resolved (fixed in 5.62-2)
trixie: resolved (fixed in 5.62-2)
OSV
bluez vulnerabilities
osv·2021-11-23·CVSS 6.5
CVE-2021-3658 [MEDIUM] bluez vulnerabilities
bluez vulnerabilities
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
OSV
CVE-2021-41229: BlueZ is a Bluetooth protocol stack for Linux
osv·2021-11-12·CVSS 6.5
CVE-2021-41229 [MEDIUM] CVE-2021-41229: BlueZ is a Bluetooth protocol stack for Linux
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/bluez/bluez/security/advisories/GHSA-3fqg-r8j5-f5xqhttps://lists.debian.org/debian-lts-announce/2021/11/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://security.netapp.com/advisory/ntap-20211203-0004/https://github.com/bluez/bluez/security/advisories/GHSA-3fqg-r8j5-f5xqhttps://lists.debian.org/debian-lts-announce/2021/11/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlhttps://security.netapp.com/advisory/ntap-20211203-0004/
2021-11-12
Published