Published: 24 Aug 2021, 06:40
Last modified:03 Jun 2026, 14:03

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Aug 2021, 06:40
Published
Vulnerability first disclosed
03 Jun 2026, 14:03
Last Modified
Vulnerability information updated

Description

linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities It was discovered that the bluetooth subsystem in the Linux kernel did not properly handle HCI device initialization failure, leading to a double-free vulnerability. An attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2021-3564) It was discovered that the bluetooth subsystem in the Linux kernel did not properly handle HCI device detach events, leading to a use-after-free vulnerability. An attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2021-3573) It was discovered that the NFC implementation in the Linux kernel did not properly handle failed connect events leading to a NULL pointer dereference. A local attacker could use this to cause a denial of service. (CVE-2021-3587)

Affected Systems

  • ubuntulinux

    < 4.15.0-154.161

  • ubuntulinux-aws

    < 4.15.0-1110.117

  • ubuntulinux-aws-hwe

    < 4.15.0-1110.117~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1122.135~14.04.1 | < 4.15.0-1122.135~16.04.1

  • ubuntulinux-azure-4.15

    < 4.15.0-1122.135

  • ubuntulinux-gcp

    < 4.15.0-1107.121~16.04.1

  • ubuntulinux-gcp-4.15

    < 4.15.0-1107.121

  • ubuntulinux-hwe

    < 4.15.0-154.161~16.04.1

  • ubuntulinux-kvm

    < 4.15.0-1098.100

  • ubuntulinux-oracle

    < 4.15.0-1079.87~16.04.1 | < 4.15.0-1079.87

  • ubuntulinux-raspi2

    < 4.15.0-1094.100

  • ubuntulinux-snapdragon

    < 4.15.0-1111.120

References (4)