HIGH

CVE-2021-1048

Google Android 2021-12-15 CVSS v3.1
CVSS
7.8
KEV

Description

In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel

Summary dbcve.org

A use-after-free vulnerability in the ep_loop_check_proc function of eventpoll.c in the Android kernel allows a local attacker to corrupt memory and escalate privileges to root without requiring user interaction or additional execution privileges.

Mitigation

Update the Android kernel to a version containing the security patch for CVE-2021-1048, or apply the upstream kernel fix to the eventpoll.c file.

Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

1%
Probability of exploitation in next 30 days
61.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE