Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-92546
HistoryNov 16, 2021 - 12:00 a.m.

BlueZ Resource Management Error Vulnerability (CNVD-2021-92546)

2021-11-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
15

0.001 Low

EPSS

Percentile

29.4%

BlueZ is a Bluetooth protocol stack written in C that is primarily used to provide support for the core Bluetooth layer and protocol. blueZ is vulnerable to a resource management error that stems from a vulnerability in the affected version of sdp’s cstate alloc buf, which allocates memory that always hangs in the cstate single-chain table and is not freed, leading to a memory leak over This can lead to memory leaks over time. An attacker could exploit the vulnerability by constantly sending sdp packets, which could eventually cause the target device’s service to crash.

CPENameOperatorVersion
bluez bluezeq5.58