CVE-2021-3588: memory contents disclosure in cli_feat_read_cb
Published Jun 10, 2021
·Updated
Last updated 24 July 2024
Other sources
The clifeatreadcb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
Affected Software
2 affected componentsFixes available
bluez bluez<5.56
debian/bluez
5.55-3.1+deb11u15.55-3.1+deb11u25.66-1+deb12u25.66-1+deb12u15.82-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/bluezto a version that resolves this vulnerability.Fixed in 5.55-3.1+deb11u1Fixed in 5.55-3.1+deb11u2Fixed in 5.66-1+deb12u2Fixed in 5.66-1+deb12u1Fixed in 5.82-1
Event History
Jun 10, 2021
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:57 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:17 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-3588.
2
What is the affected software?
The affected software is bluez.
3
What is the severity of CVE-2021-3588?
The severity of CVE-2021-3588 is not specified.
4
How does this vulnerability occur?
The vulnerability occurs due to the lack of bounds checks on the 'offset' variable in the cli_feat_read_cb() function.
5
How can I fix this vulnerability?
To fix this vulnerability, update bluez to version 5.53-0ubuntu3.2 or later.