HIGH
CVE-2021-1048
CVSS
7.8
KEV
Description
In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel
Summary dbcve.org
A use-after-free vulnerability in the ep_loop_check_proc function of eventpoll.c in the Android kernel allows a local attacker to corrupt memory and escalate privileges to root without requiring user interaction or additional execution privileges.
Mitigation
Update the Android kernel to a version containing the security patch for CVE-2021-1048, or apply the upstream kernel fix to the eventpoll.c file.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
1%
Probability of exploitation in next 30 days
61.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.