CVE-2021-31615
Linux Ubuntu vulnerability analysis and mitigation

Overview

Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications versions 4.0 through 5.2 contain a vulnerability that allows packet injection attacks. The vulnerability was disclosed on June 25, 2021, affecting Bluetooth Core Specification implementations from version 4.0 to 5.2 (NVD).

Technical details

The vulnerability allows an adjacent attacker to inject a crafted packet during the receive window of the listening device before the transmitting device initiates its packet transmission. This can be achieved by spoofing the Central's address during the time between when the Peripheral starts receiving a packet from the Central and when the Central actually transmits during each connection interval. The success rate of packet injection increases with greater window widening values, such as when the connection interval increases (Bluetooth Advisory).

Impact

A successful exploitation can allow an attacker to achieve full man-in-the-middle (MITM) status without terminating the link. When targeting devices that are establishing or using encrypted links, crafted packets may be used to terminate an existing link, but will not compromise the confidentiality or integrity of the link (NVD).

Mitigation and workarounds

The Bluetooth SIG strongly recommends that implementations verify the use of encryption in any profile that requires it under specification. Vendor-specific profile implementations with custom attributes should require encryption for both read and write operations on those characteristics by default. Users should ensure they have installed the latest recommended updates from device and operating system manufacturers (Bluetooth Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64460HIGH7.5
  • DjangoDjango
  • python-django
NoYesDec 02, 2025
CVE-2025-13735HIGH7.4
  • Linux UbuntuLinux Ubuntu
  • linux-aws-fips
NoNoNov 26, 2025
CVE-2025-13372MEDIUM4.3
  • DjangoDjango
  • python-django
NoYesDec 02, 2025
CVE-2025-2486LOW3.7
  • Linux DebianLinux Debian
  • edk2
NoYesNov 26, 2025
CVE-2025-66270N/AN/A
  • Linux DebianLinux Debian
  • kdeconnect
NoYesNov 27, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management