PT-2020-7003 · Google+1 · Android Kernel+1
Published
2020-11-13
·
Updated
2021-11-19
·
CVE-2021-0938
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android kernel
Description
The issue is related to the use of uninitialized data in the memzero explicit function of compiler-clang.h, which could lead to a bypass of defense in depth. This might result in local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations
For Android kernel, consider applying the upstream kernel fix to resolve the issue.
As a temporary workaround, restrict access to sensitive data to minimize the risk of information disclosure until a patch is available.
Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel
Astra Linux