PT-2021-1508 · Google+6 · Android Kernel+6

Published

2021-01-18

·

Updated

2021-11-03

·

CVE-2021-0512

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Android kernel
Description: The issue is related to a heap buffer overflow in the hidinput change resolution multipliers function of hid-input.c, which can lead to a local escalation of privilege without requiring additional execution privileges. User interaction is not needed for exploitation.
Recommendations: For Android kernel, consider applying the fix from the upstream kernel to resolve the issue. As a temporary workaround, consider restricting access to the hidinput change resolution multipliers function until a patch is available. No other specific mitigation measures are provided for this issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4056
ASB-A-173843328
BDU:2021-03320
CESA-2021_4056
CESA-2021_4088
CESA-2021_4122
CVE-2021-0512
DLA-2689-1
OPENSUSE-SU-2021:2305-1
OPENSUSE-SU-2021:2352-1
OPENSUSE-SU-2021:2427-1
OPENSUSE-SU-2021_2305-1
OPENSUSE-SU-2021_2352-1
OPENSUSE-SU-2021_2427-1
RHSA-2021:3443
RHSA-2021:3445
RHSA-2021:3446
RHSA-2021:4056
RHSA-2021:4088
RHSA-2021:4122
RHSA-2021:4750
RHSA-2021_4056
RHSA-2021_4088
RLSA-2021:4056
RLSA-2021:4088
SUSE-SU-2021:14764-1
SUSE-SU-2021:2303-1
SUSE-SU-2021:2305-1
SUSE-SU-2021:2321-1
SUSE-SU-2021:2324-1
SUSE-SU-2021:2325-1
SUSE-SU-2021:2332-1
SUSE-SU-2021:2344-1
SUSE-SU-2021:2349-1
SUSE-SU-2021:2352-1
SUSE-SU-2021:2361-1
SUSE-SU-2021:2367-1
SUSE-SU-2021:2368-1
SUSE-SU-2021:2372-1
SUSE-SU-2021:2377-1
SUSE-SU-2021:2387-1
SUSE-SU-2021:2406-1
SUSE-SU-2021:2421-1
SUSE-SU-2021:2422-1
SUSE-SU-2021:2426-1
SUSE-SU-2021:2427-1
SUSE-SU-2021:2433-1
SUSE-SU-2021:2451-1
SUSE-SU-2021:2453-1
SUSE-SU-2021_14764-1
SUSE-SU-2021_2332-1
SUSE-SU-2021_2344-1
SUSE-SU-2021_2361-1
SUSE-SU-2021_2367-1
SUSE-SU-2021_2372-1
SUSE-SU-2021_2377-1
SUSE-SU-2021_2387-1
SUSE-SU-2021_2433-1

Affected Products

Almalinux
Android Kernel
Astra Linux
Centos
Red Hat
Rocky Linux
Suse