CVE-2021-32399: Race Condition
A flaw was found in the Linux kernel’s handling of the removal of Bluetooth HCI controllers. This flaw allows an attacker with a local account to exploit a race condition, leading to corrupted memory and possible privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
net/bluetooth/hcirequest.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-32399?
CVE-2021-32399 is considered a medium severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2021-32399?
To fix CVE-2021-32399, upgrade to the recommended kernel versions specified by your distribution.
What systems are affected by CVE-2021-32399?
CVE-2021-32399 affects various versions of the Linux kernel and specific Red Hat packages.
Can CVE-2021-32399 be exploited remotely?
No, CVE-2021-32399 requires a local account for exploitation, limiting its attack surface.
What impact does CVE-2021-32399 have on systems?
CVE-2021-32399 can lead to memory corruption and potential privilege escalation, impacting system integrity.