CVE-2019-8921 is a medium-severity vulnerability in BlueZ through version 5.48, affecting various Linux distributions including Debian. It allows an attacker to leak arbitrary heap data due to improper handling of SVC_ATTR_REQ in the SDP implementation. An attacker can craft a malicious CSTATE to trick the server into returning more data than its buffer can hold. The vulnerability has a CVSS score of 6.5 (MEDIUM) with an attack vector of adjacent network and high confidentiality impact. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.48CPE matchmatch criteria | cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.