A use-after-free flaw in the Linux kernel Bluetooth HCI SCO subsystem, tracked as CVE-2021-3640, can allow a local privileged attacker to crash a host or escalate privileges. The vulnerability stems from a race involving sco_sock_sendmsg() and sco_conn_del(); it can be triggered through UFFDIO_REGISTER or a comparable mechanism by an attacker holding CAP_NET_ADMIN in the initial user namespace.
Red Hat assigned the issue a Moderate severity rating with a CVSS v3.1 score of 6.7 and classified it as CWE-825, expired pointer dereference. Fixed kernel and kernel-rt packages were released for Red Hat Enterprise Linux 8 and 9, with further fixes for RHEL 8.6 EUS and Red Hat Virtualization; RHEL 6 is unaffected, while out-of-support RHEL 7 kernel variants should be treated as potentially affected.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:7444 for the RHEL 8 kernel-rt and RHSA-2022:7683 for the RHEL 8 kernel, addressing the Bluetooth SCO use-after-free vulnerability CVE-2021-3640.
Red Hat issued RHSA-2024:0724 to fix CVE-2021-3640 in the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Red Hat issued RHSA-2022:8267 for the RHEL 9 kernel and RHSA-2022:7933 for the RHEL 9 kernel-rt to fix CVE-2021-3640.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.