PT-2020-7003 · Google+1 · Android Kernel+1

Published

2020-11-13

·

Updated

2021-11-19

·

CVE-2021-0938

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to the use of uninitialized data in the memzero explicit function of compiler-clang.h, which could lead to a bypass of defense in depth. This might result in local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android kernel, consider applying the upstream kernel fix to resolve the issue. As a temporary workaround, restrict access to sensitive data to minimize the risk of information disclosure until a patch is available.

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00832
CVE-2021-0938
OESA-2021-1433

Affected Products

Android Kernel
Astra Linux