Use-after-free in Google Android - CVE-2021-1048

 

Use-after-free in Google Android - CVE-2021-1048

Published: November 3, 2021


Vulnerability identifier: #VU57890
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1048
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a malicious application to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in the Android kernel component within the epoll_loop_check_proc() function. A malicious application can trigger a use-after-free error and execute arbitrary code with kernel privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Google Android
Oracle VM Server for x86

How to mitigate CVE-2021-1048

Install updates from vendor's website.

Google Android - addressed in versions 9 2021-11-06, 10 2021-11-06, 11 2021-11-06, 12 2021-11-06

External References

Related Security Bulletins