CVE-2021-3752
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.7%
exploitation probability
1.7%top 23% of all CVEs
observed exploitation
nono source reports it
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected products
n/a · kernelReferences
https://bugzilla.redhat.com/show_bug.cgi?id=1999544https://lists.debian.org/debian-lts-announce/2022/03/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlhttps://lore.kernel.org/lkml/20211115165435.133245729%40linuxfoundation.org/https://security.netapp.com/advisory/ntap-20220318-0009/https://www.debian.org/security/2022/dsa-5096https://www.openwall.com/lists/oss-security/2021/09/15/4https://www.oracle.com/security-alerts/cpujul2022.html