CVE-2021-43400: Use After Free
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-43400?
CVE-2021-43400 is a vulnerability discovered in BlueZ 5.61 that allows for a use-after-free condition when a client disconnects during D-Bus processing of a WriteValue call.
How severe is CVE-2021-43400?
CVE-2021-43400 has a severity rating of 9.1, which is considered critical.
What software versions are affected by CVE-2021-43400?
BlueZ 5.61 and Debian Linux 10.0 are affected by CVE-2021-43400.
How can I fix CVE-2021-43400?
To fix CVE-2021-43400, it is recommended to update to a patched version of BlueZ 5.61 or Debian Linux 10.0.
Where can I find more information about CVE-2021-43400?
More information about CVE-2021-43400 can be found at the following references: [Link 1](https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=838c0dc7641e1c991c0f3027bf94bee4606012f8), [Link 2](https://lists.debian.org/debian-lts-announce/2022/10/msg00026.html).