CVE-2021-3564
Aliases:UBUNTU-CVE-2021-3564DEBIAN-CVE-2021-3564CGA-23h6-prjx-cxgwCGA-2fh6-rgr7-h655CGA-2fj5-5jcf-5f5vCGA-2g57-gr4r-xw67CGA-2jwh-95j9-qvv2CGA-2wmp-qjvx-5q6gCGA-2xv6-wmrh-66m4CGA-3387-996g-82mcCGA-3658-q7cp-mp7jCGA-3j86-7gr3-wrrwCGA-3q9c-7779-8j6pCGA-4945-x77x-j5f3CGA-4gxx-2364-629xCGA-4prp-23gh-qm6jCGA-52wh-m5mq-c5jvCGA-52xp-5pg9-p3hcCGA-5363-j7r6-9752CGA-5483-58ff-cvr2CGA-587c-qqj3-8532CGA-59xw-2q39-hc24CGA-5vc2-g68q-gpjpCGA-5w5c-c599-xmgwCGA-629f-56rh-vq2hCGA-63r7-v97x-p9w6CGA-644h-873c-qr7pCGA-6cvv-86fr-6f5mCGA-6gr6-6h7f-q9fjCGA-6jgg-5ww5-fhf2CGA-6mxw-v69h-j6mcCGA-6qjj-wcr4-ph76CGA-6qvq-9rhp-ph85CGA-7289-2p6h-j3ghCGA-729x-h9hr-h465CGA-72j7-w8fc-56cqCGA-78gg-5gx6-hxxhCGA-7qhp-xc9r-3v9gCGA-87v8-x335-mpjfCGA-8hp9-r8v3-j9pwCGA-8jgx-p823-m2c9CGA-8pxm-gpcq-4pxrCGA-9256-847q-g3vhCGA-95rj-gj33-p35fCGA-988m-wqfp-94f6CGA-98f2-m5vw-532gCGA-9f54-vffc-64fcCGA-9fvx-9g56-wv8hCGA-9gxv-69j2-jm6gCGA-9hv4-j443-3rvgCGA-9jpg-9j93-m2mjCGA-9pfc-2g23-fq9fCGA-9x4v-mjpj-m5m4CGA-c3ph-hfcw-gq8mCGA-c8h8-p27q-8wwqCGA-crg8-9ccv-2fvcCGA-cvwx-gfpj-8p7qCGA-f5xq-m775-fjqpCGA-ffh3-6m96-27j6CGA-fr9h-mj68-rx34CGA-frxp-xwv5-r68vCGA-fx65-w6f2-qchjCGA-fxhp-63h3-r8fvCGA-fxqq-h5v3-j2x4CGA-g2q5-f6pr-4rcfCGA-g8ww-39r6-p46gCGA-gjm7-65qg-v4x8CGA-gqjj-r5jp-gm2mCGA-gv4h-25jg-cmx9CGA-h6c2-mr9f-636hCGA-hmf7-pp25-3296CGA-hppp-2r46-2x4gCGA-hq5w-83qr-h864CGA-j3hv-mcm2-7cf9CGA-j62q-wcgm-rxjrCGA-j8p3-h42p-5rm6CGA-jc4j-wr5m-37wqCGA-jgxf-j6v8-78f7CGA-jhvj-2j93-979qCGA-jqj7-94p4-p8cwCGA-jv7q-95jg-c4wjCGA-m6j5-2gmq-f765CGA-m6jv-8p7j-x8rhCGA-m72f-pmx6-fvcgCGA-mm97-rp5g-6mprCGA-p4p9-26j8-pf22CGA-p6hg-6rq5-5mgrCGA-ph43-phrg-rcxxCGA-phmq-74mj-8m86CGA-pq8x-hhg7-hf6jCGA-qghg-grfv-93g7CGA-qh56-mhhj-6chmCGA-qhp9-v3pf-mxj5CGA-r226-mmp7-r5cqCGA-r2w8-7qx2-wpgmCGA-r4cv-fc5j-g353CGA-r6v8-2rpw-6cmgCGA-rm5c-3c7x-h8c8CGA-rmqr-q6hj-67ghCGA-v28w-xv4v-wv36CGA-v876-9pj2-m2wcCGA-vg3p-cj74-j5c3CGA-vpf5-rqf4-9rcxCGA-vqpx-p4hh-6q55CGA-vvq6-4r85-cq3vCGA-w2q4-r63q-4f54CGA-w4pr-pp72-m48wCGA-w7r9-7rvc-c8v9CGA-wqg4-r837-prvhCGA-x583-74m9-j6cvCGA-x956-vmhc-rqfxCGA-x9mw-wc52-g9jfCGA-xc5m-f26m-r5fjCGA-xfcg-63w8-x2qqCGA-xvvx-8h7v-h59gCGA-xvxc-27f5-w8cgCGA-xx8w-xmj8-79wxCGA-3mx8-f584-f379CGA-f59q-wwj6-7p9gCGA-2cwg-mrjp-q3w5CGA-2gf8-qrrw-fqgrCGA-2mr8-5v6v-9g45CGA-3j69-36xx-qxm8CGA-3wxw-q2mx-gmfgCGA-45qq-4g4w-q995CGA-49mj-q76c-gmxfCGA-54rh-66jm-w4rwCGA-pw5p-j8hh-9c5gCGA-vgpx-4r5h-7672CGA-w4w8-gjqv-f5vmCGA-wm5q-mvwf-jjjmCGA-x5m8-mg84-4259CGA-xp7g-g44j-q2w3CGA-fwfc-7rcj-35hcCGA-2rfx-p6qw-7hg7CGA-3256-g34g-hvf9CGA-37w3-27rh-mx34CGA-6mpg-778r-hgrcCGA-8hmc-xxjc-frgwCGA-qxp5-9479-fjr9CGA-5799-qwvw-qpxxCGA-p789-wj9p-rqqgCGA-x6vh-88h6-qv8w
Advisory lineage Upstream: 0 Downstream: 26
Modified
Published: 08 Jun 2021, 11:59
Last modified:03 Aug 2024, 17:01
Vulnerability Summary
Overall Risk (default)
medium
32/100 CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.48% LOW
0% probability +0.46%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected
Timeline
08 Jun 2021, 11:59
Published
Vulnerability first disclosed
03 Aug 2024, 17:01
Last Modified
Vulnerability information updated
Description
A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.48%• Percentile: 41%
Techniques & Countermeasures
- CWE-415•Double Free
The product calls free() twice on the same memory address.
Affected Systems
- chainguard•hyperv-daemons-6.18
< 0
- chainguard•hyperv-daemons-generic
< 0
- chainguard•linux-aws-6.12
< 6.12.65-r0 | < 0
- chainguard•linux-aws-6.12-boot-installed
< 0
- chainguard•linux-aws-6.12-fips-boot-installed
< 0
- chainguard•linux-aws-6.12-headers
< 0
- chainguard•linux-aws-6.12-modules
< 0
- chainguard•linux-aws-6.18
< 6.18.10-r0 | < 0
- chainguard•linux-aws-6.18-boot-installed
< 0
- chainguard•linux-aws-6.18-fips-boot-installed
< 0
- chainguard•linux-aws-6.18-headers
< 0
- chainguard•linux-aws-6.18-modules
< 0
- chainguard•linux-aws-generic
< 6.18.5-r0 | < 0
- chainguard•linux-aws-generic-boot-installed
< 0
- chainguard•linux-aws-generic-fips-boot-installed
< 0
- chainguard•linux-aws-generic-headers
< 0
- chainguard•linux-aws-generic-modules
< 0
- chainguard•linux-azure-6.12
< 6.12.65-r1 | < 0
- chainguard•linux-azure-6.18
< 0
- chainguard•linux-azure-6.18-boot-installed
< 0
- chainguard•linux-azure-6.18-fips-boot-installed
< 0
- chainguard•linux-azure-6.18-headers
< 0
- chainguard•linux-azure-6.18-modules
< 0
- chainguard•linux-azure-generic
< 6.18.5-r0 | < 0
- chainguard•linux-azure-generic-boot-installed
< 0
- chainguard•linux-azure-generic-fips-boot-installed
< 0
- chainguard•linux-azure-generic-headers
< 0
- chainguard•linux-azure-generic-modules
< 0
- chainguard•linux-desktop-6.18
all
- chainguard•linux-desktop-6.18-bootc
all
- chainguard•linux-desktop-6.18-bootc-boot-installed
all
- chainguard•linux-desktop-6.18-headers
all
- chainguard•linux-desktop-6.18-modules
all
- chainguard•linux-desktop-7.2
all
- chainguard•linux-desktop-7.2-bootc
all
- chainguard•linux-desktop-7.2-bootc-boot-installed
all
- chainguard•linux-desktop-7.2-modules
all
- chainguard•linux-firecracker-6.18
all
- chainguard•linux-gcp-6.12
< 6.12.65-r0 | < 0
- chainguard•linux-gcp-6.18
< 6.18.10-r0 | < 0
- chainguard•linux-gcp-6.18-boot-installed
< 0
- chainguard•linux-gcp-6.18-fips-boot-installed
< 0
- chainguard•linux-gcp-6.18-headers
< 0
- chainguard•linux-gcp-6.18-modules
< 0
- chainguard•linux-gcp-generic
< 6.18.5-r0 | < 0
- chainguard•linux-gcp-generic-boot-installed
< 0
- chainguard•linux-gcp-generic-fips-boot-installed
< 0
- chainguard•linux-gcp-generic-headers
< 0
- chainguard•linux-gcp-generic-modules
< 0
- chainguard•linux-qemu-6.12
< 6.12.71-r0 | < 0
Showing first 50 affected entries in server-rendered view.
References (17)
- http://www.openwall.com/lists/oss-security/2021/05/25/1
- http://www.openwall.com/lists/oss-security/2021/06/01/2
- https://bugzilla.redhat.com/show_bug.cgi?id=1964139
- https://www.openwall.com/lists/oss-security/2021/05/25/1
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
- https://ubuntu.com/security/CVE-2021-3564
- https://lore.kernel.org/linux-bluetooth/20210525123902.189012-1-gregkh@linuxfoundation.org/
- https://ubuntu.com/security/notices/USN-5015-1
- https://ubuntu.com/security/notices/USN-5044-1
- https://ubuntu.com/security/notices/USN-5045-1
- https://ubuntu.com/security/notices/USN-5046-1
- https://ubuntu.com/security/notices/USN-5050-1
- https://ubuntu.com/security/notices/USN-5299-1
- https://ubuntu.com/security/notices/USN-5343-1
- https://www.cve.org/CVERecord?id=CVE-2021-3564
- https://security-tracker.debian.org/tracker/CVE-2021-3564