bluetoothd from bluez incorrectly saves adapters' Discoverable status when a...
Vulnerability Description
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3658
Credits & Attribution
No credits recorded in the NVD database.
References
- https://gitlab.gnome.org/GNOME/gnome-bluetooth/-/issues/89
- https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=b497b5942a8beb8f89ca1c359c54ad67ec843055
- https://github.com/bluez/bluez/commit/b497b5942a8beb8f89ca1c359c54ad67ec843055
- https://bugzilla.redhat.com/show_bug.cgi?id=1984728
- https://security.netapp.com/advisory/ntap-20220407-0002/