CVE-2021-3752: Race Condition
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
Use-after-free may allow local user to partially escalate privileges.
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-3752?
CVE-2021-3752 has been rated as High severity due to potential for system crashes and privilege escalation.
How do I fix CVE-2021-3752?
To address CVE-2021-3752, you should update your Linux kernel to the latest versions specified by your distribution, including kernel-rt and kernel for Red Hat and Debian.
What systems are affected by CVE-2021-3752?
CVE-2021-3752 affects various Linux distributions including Red Hat and Debian, particularly versions of the kernel from 2.6.12 to 5.15.3.
What types of vulnerabilities does CVE-2021-3752 represent?
CVE-2021-3752 is a use-after-free vulnerability, caused by a race condition in the Bluetooth subsystem of the Linux kernel.
Can exploitation of CVE-2021-3752 lead to remote access?
Exploitation of CVE-2021-3752 could potentially allow an attacker to escalate privileges on the affected system.