CVE-2021-43400Use After Free in Bluez

CWE-416Use After Free7 documents6 sources
Severity
9.1CRITICALNVD
OSV6.5
EPSS
0.2%
top 61.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateMay 24

Description

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

debiandebian/bluez< bluez 5.62-1 (bookworm)
Debianbluez/bluez< 5.55-3.1+deb11u2+3
Ubuntubluez/bluez< 5.48-0ubuntu3.6+1
NVDbluez/bluez5.61

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xgf8-98pj-cm5c: An issue was discovered in gatt-database2022-05-24
OSV
bluez vulnerabilities2021-11-23
OSV
CVE-2021-43400: An issue was discovered in gatt-database2021-11-04

📋Vendor Advisories

3
Ubuntu
BlueZ vulnerabilities2021-11-23
Red Hat
bluez: use-after-free in gatt-database.c2021-11-05
Debian
CVE-2021-43400: bluez - An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can o...2021