Medium severity6.5NVD Advisory· Published Mar 2, 2022· Updated Apr 15, 2026
CVE-2021-3658
CVE-2021-3658
Description
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
Affected products
2- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Patches
2d61f9dc54c04b497b5942a8bhttps://github.com/bluez/bluezvia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
6- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- git.kernel.org/pub/scm/bluetooth/bluez.git/commit/nvdPatchThird Party Advisory
- github.com/bluez/bluez/commit/b497b5942a8beb8f89ca1c359c54ad67ec843055nvdPatchThird Party Advisory
- gitlab.gnome.org/GNOME/gnome-bluetooth/-/issues/89nvdIssue TrackingPatchThird Party Advisory
- security.netapp.com/advisory/ntap-20220407-0002/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlnvd
News mentions
0No linked articles in our index yet.