
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability identified as CVE-2021-34981 was discovered in the Linux kernel's CAPI over Bluetooth connection code. This flaw specifically exists within the CMTP (CAPI Message Transfer Protocol) module and was assigned a CVSS v3.1 base score of 7.5, indicating a moderate to high severity issue (Ubuntu CVE, Red Hat CVE).
The vulnerability stems from the lack of validation when checking the existence of an object prior to performing free operations on the object in the CMTP module. This can lead to a double-free condition when CAPI (ISDN) hardware connection fails. The issue has been assigned a CVSS vector of CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H, indicating local access is required with high attack complexity and high privileges required (ZDI Advisory, Red Hat CVE).
If successfully exploited, this vulnerability allows an attacker to escalate privileges and execute code in the context of the kernel. The impact is considered high for confidentiality, integrity, and availability, potentially giving attackers complete control over the affected system (ZDI Advisory).
The vulnerability requires local access to the system and high privileges for exploitation. An attacker must first obtain the ability to execute high-privileged code on the target system to exploit this vulnerability. Additionally, CAP_NET_ADMIN privileges are required (Ubuntu CVE, ZDI Advisory).
To mitigate this vulnerability, system administrators can disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. This can be achieved using system-wide modprobe rules. Alternatively, Bluetooth can be disabled within the hardware or at BIOS level, which will prevent the kernel from detecting Bluetooth hardware on the system. The vulnerability was fixed in kernel version 5.10.42 (Red Hat CVE, ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."