Medium severity6.5NVD Advisory· Published Mar 2, 2022· Updated Apr 15, 2026
CVE-2021-3658
CVE-2021-3658
Description
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
26- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- osv-coords23 versionspkg:rpm/opensuse/bluez&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/bluez&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/bluez&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3pkg:rpm/suse/bluez&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/bluez&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/bluez&distro=SUSE%20Manager%20Server%204.1
< 5.55-150300.3.14.1+ 22 more
- (no CPE)range: < 5.55-150300.3.14.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.55-150300.3.14.1
- (no CPE)range: < 5.55-150300.3.14.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150000.5.41.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.55-150300.3.14.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.48-150200.13.17.1
- (no CPE)range: < 5.48-150200.13.17.1
Patches
Vulnerability mechanics
References
6- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- git.kernel.org/pub/scm/bluetooth/bluez.git/commit/nvdPatchThird Party Advisory
- github.com/bluez/bluez/commit/b497b5942a8beb8f89ca1c359c54ad67ec843055nvdPatchThird Party Advisory
- gitlab.gnome.org/GNOME/gnome-bluetooth/-/issues/89nvdIssue TrackingPatchThird Party Advisory
- security.netapp.com/advisory/ntap-20220407-0002/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlnvd
News mentions
0No linked articles in our index yet.