CVE-2021-43400
published 2021-11-04CVE-2021-43400: An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.54%
72.4th percentile
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | — | — |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u2 | 5.55-3.1+deb11u2 |
| bluez | bluez | >= 0 < 5.62-1 | 5.62-1 |
| bluez | bluez | >= 0 < 5.62-1 | 5.62-1 |
| bluez | bluez | >= 0 < 5.62-1 | 5.62-1 |
| bluez | bluez | >= 0 < 5.48-0ubuntu3.6 | 5.48-0ubuntu3.6 |
| bluez | bluez | >= 0 < 5.53-0ubuntu3.4 | 5.53-0ubuntu3.4 |
| debian | bluez | < bluez 5.62-1 (bookworm) | bluez 5.62-1 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2021-11-23·CVSS 6.5
CVE-2021-3658 [MEDIUM] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: Several security issues were fixed in BlueZ.
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
Instructions: In gene
Red Hat
bluez: use-after-free in gatt-database.c
vendor_redhat·2021-11-05·CVSS 9.1
CVE-2021-43400 [CRITICAL] CWE-416 bluez: use-after-free in gatt-database.c
bluez: use-after-free in gatt-database.c
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
Package: bluez (Red Hat Enterprise Linux 6) - Not affected
Package: bluez (Red Hat Enterprise Linux 7) - Not affected
Package: bluez (Red Hat Enterprise Linux 8) - Not affected
Package: bluez (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-43400: bluez - An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can o...
vendor_debian·2021·CVSS 9.1
CVE-2021-43400 [CRITICAL] CVE-2021-43400: bluez - An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can o...
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
Scope: local
bookworm: resolved (fixed in 5.62-1)
bullseye: resolved (fixed in 5.55-3.1+deb11u2)
forky: resolved (fixed in 5.62-1)
sid: resolved (fixed in 5.62-1)
trixie: resolved (fixed in 5.62-1)
GHSA
GHSA-xgf8-98pj-cm5c: An issue was discovered in gatt-database
ghsa_unreviewed·2022-05-24
CVE-2021-43400 [CRITICAL] CWE-416 GHSA-xgf8-98pj-cm5c: An issue was discovered in gatt-database
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
OSV
bluez vulnerabilities
osv·2021-11-23·CVSS 6.5
CVE-2021-3658 [MEDIUM] bluez vulnerabilities
bluez vulnerabilities
It was discovered that BlueZ incorrectly handled the Discoverable status
when a device is powered down. This could result in devices being powered
up discoverable, contrary to expectations. This issue only affected Ubuntu
20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)
It was discovered that BlueZ incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause BlueZ to consume
resources, leading to a denial of service. (CVE-2021-41229)
It was discovered that the BlueZ gatt server incorrectly handled
disconnects. A remote attacker could possibly use this issue to cause
BlueZ to crash, leading to a denial of service. (CVE-2021-43400)
OSV
CVE-2021-43400: An issue was discovered in gatt-database
osv·2021-11-04·CVSS 9.1
CVE-2021-43400 [CRITICAL] CVE-2021-43400: An issue was discovered in gatt-database
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=838c0dc7641e1c991c0f3027bf94bee4606012f8https://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=838c0dc7641e1c991c0f3027bf94bee4606012f8https://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00022.html
2021-11-04
Published