Description
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2827-1 | bluez security update |
Debian DLA |
DLA-3157-1 | bluez security update |
Debian DLA |
DLA-3879-1 | bluez security update |
EUVD |
EUVD-2021-28288 | BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash. |
Ubuntu USN |
USN-5155-1 | BlueZ vulnerabilities |
References
History
Tue, 04 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-04T16:09:18.907Z
Reserved: 2021-09-15T00:00:00.000Z
Link: CVE-2021-41229
No data.
Status : Modified
Published: 2021-11-12T23:15:08.857
Modified: 2025-11-04T16:15:44.420
Link: CVE-2021-41229
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN