CVE-2021-3658
low
CVSS v3
—
CVSS v2
—
VIR risk
2.5
Description
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-3658.html
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-3658
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 5.61-1 |
| debian | bullseye | fixed | 5.55-3.1+deb11u2 |
| debian | forky | fixed | 5.61-1 |
| debian | sid | fixed | 5.61-1 |
| debian | trixie | fixed | 5.61-1 |
| arch | fixed | 5.61-1 | |
| sles | affected | |
References
Verify integrity in audit chain (admin only). AS-IS.