PT-2021-3402 · Google+5 · Android Kernel+5

Published

2021-05-18

·

Updated

2021-07-22

·

CVE-2021-0605

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel versions (affected versions not specified)
Description The issue is related to a possible out-of-bounds read in the pfkey dump function of af key.c due to a missing bounds check. This could lead to local information disclosure in the kernel, requiring System execution privileges for exploitation. No user interaction is needed for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1578
BDU:2021-03253
CESA-2021_1578
CESA-2021_1739
CVE-2021-0605
OPENSUSE-SU-2021:2305-1
OPENSUSE-SU-2021:2352-1
OPENSUSE-SU-2021:2427-1
OPENSUSE-SU-2021_2305-1
OPENSUSE-SU-2021_2352-1
OPENSUSE-SU-2021_2427-1
RHSA-2021:1578
RHSA-2021:1739
RHSA-2021_1578
RHSA-2021_1739
SUSE-SU-2021:2303-1
SUSE-SU-2021:2305-1
SUSE-SU-2021:2321-1
SUSE-SU-2021:2324-1
SUSE-SU-2021:2325-1
SUSE-SU-2021:2344-1
SUSE-SU-2021:2349-1
SUSE-SU-2021:2352-1
SUSE-SU-2021:2367-1
SUSE-SU-2021:2368-1
SUSE-SU-2021:2377-1
SUSE-SU-2021:2406-1
SUSE-SU-2021:2421-1
SUSE-SU-2021:2422-1
SUSE-SU-2021:2426-1
SUSE-SU-2021:2427-1
SUSE-SU-2021:2433-1
SUSE-SU-2021:2451-1

Affected Products

Almalinux
Android Kernel
Astra Linux
Centos
Red Hat
Suse