CVE-2021-41229
Summary
| CVE | CVE-2021-41229 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-12 23:15:00 UTC |
| Updated | 2022-11-07 17:25:00 UTC |
| Description | BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-41229 BlueZ Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] [DLA 2827-1] bluez security update |
MLIST |
lists.debian.org |
|
| There is a memory leak vulnerability in the sdp protocol, which will cause resource-consuming dos · Advisory · bluez/bluez · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] [DLA 3157-1] bluez security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161227 Oracle Enterprise Linux Security Update for bluez (ELSA-2022-2081)
- 178914 Debian Security Update for bluez (DLA 2827-1)
- 181160 Debian Security Update for bluez (DLA 3157-1)
- 182795 Debian Security Update for bluez (CVE-2021-41229)
- 198579 Ubuntu Security Notification for BlueZ Vulnerabilities (USN-5155-1)
- 240281 Red Hat Update for bluez (RHSA-2022:2081)
- 754882 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2023:3689-1)
- 755635 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2024:0167-1)
- 755636 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2024:0166-1)
- 940544 AlmaLinux Security Update for bluez (ALSA-2022:2081)
- 960251 Rocky Linux Security Update for bluez (RLSA-2022:2081)