« List of all CVEs

CVE-2021-3658

Published: 3/2/2022 Last updated: 8/3/2024 Reserved: 7/22/2021

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-bluetooth mindstorm

Products affected (1)

Product Vendor Version
bluez n/a < tvOS 13.4.5

References (10)