PT-2021-7375 · Google+7 · Android Kernel+7

Published

2021-02-13

·

Updated

2022-09-19

·

CVE-2021-0941

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a possible out of bounds read due to a use after free in the bpf skb change head function of filter.c. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. The vulnerability is associated with an error in reading beyond memory boundaries, which may allow an attacker to access potentially confidential information or cause a system crash or leak internal kernel information.
Recommendations For Android kernel, consider disabling the bpf skb change head function as a temporary workaround until a patch is available. Restrict access to sensitive information and system resources to minimize the risk of exploitation. Apply configuration changes to limit the privileges of local users and reduce the potential impact of the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1988
BDU:2022-05836
CESA-2022_1975
CESA-2022_1988
CVE-2021-0941
OESA-2022-1484
OPENSUSE-SU-2021:1501-1
OPENSUSE-SU-2021:3806-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021:3941-1
OPENSUSE-SU-2021_1501-1
OPENSUSE-SU-2021_3806-1
OPENSUSE-SU-2021_3876-1
OPENSUSE-SU-2021_3941-1
RHSA-2022:1975
RHSA-2022:1988
RHSA-2022_1975
RHSA-2022_1988
RLSA-2022:1975
RLSA-2022:1988
SUSE-SU-2021:3806-1
SUSE-SU-2021:3807-1
SUSE-SU-2021:3848-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3877-1
SUSE-SU-2021:3933-1
SUSE-SU-2021:3941-1
SUSE-SU-2021:3969-1
SUSE-SU-2021:3972-1
SUSE-SU-2021:3978-1
SUSE-SU-2021:3979-1
SUSE-SU-2021:3992-1
SUSE-SU-2021:4021-1
SUSE-SU-2021:4038-1
SUSE-SU-2021:4090-1
SUSE-SU-2021:4099-1
SUSE-SU-2021_3806-1
SUSE-SU-2021_3807-1
SUSE-SU-2021_3848-1
SUSE-SU-2021_3877-1
SUSE-SU-2021_3933-1
SUSE-SU-2021_3941-1
SUSE-SU-2021_3979-1
SUSE-SU-2021_4038-1
SUSE-SU-2021_4090-1
SUSE-SU-2021_4099-1

Affected Products

Almalinux
Android Kernel
Astra Linux
Centos
Red Hat
Red Os
Rocky Linux
Suse