CVE-2021-3658

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/03/2022
Last modified:
15/04/2026

Description

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:* 5.61 (excluding)
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*