« List of all CVEs

CVE-2021-3658

Published: 3/2/2022 Last updated: 4/15/2026 Reserved: 7/22/2021

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6.5 Medium CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Opam packages affected (2)

conf-bluetooth mindstorm

Products affected (2)

Product Vendor Version
bluez n/a n/a
bluez n/a n/a

References (22)