CVE-2021-0318
published 2021-01-11CVE-2021-0318: In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.2th percentile
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-8.1, Android-10, Android-11; Android ID: A-168211968.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_native | >= 10:0 < 10:2021-01-01 | 10:2021-01-01 |
| platform | frameworks_native | >= 11:0 < 11:2021-01-01 | 11:2021-01-01 |
| platform | frameworks_native | >= 8.1:0 < 8.1:2021-01-01 | 8.1:2021-01-01 |
| platform | frameworks_native | >= 9:0 < 9:2021-01-01 | 9:2021-01-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-0318: Android Security Bulletin 2021-01-01
CVE: CVE-2021-0318
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
vendor_android·2021-01-01·CVSS 7.8
CVE-2021-0318 [HIGH] CVE-2021-0318: Android Security Bulletin 2021-01-01
CVE: CVE-2021-0318
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
Android Security Bulletin 2021-01-01
CVE: CVE-2021-0318
Severity: HIGH
Type: EoP
Affected AOSP versions: 8.1, 9, 10, 11
References: A-168211968
GHSA
GHSA-526j-q77m-37w5: In appendEventsToCacheLocked of SensorEventConnection
ghsa_unreviewed·2022-05-24
CVE-2021-0318 [HIGH] CWE-787 GHSA-526j-q77m-37w5: In appendEventsToCacheLocked of SensorEventConnection
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-8.1, Android-10, Android-11; Android ID: A-168211968.
OSV
CVE-2021-0318: In appendEventsToCacheLocked of SensorEventConnection
osv·2021-01-01
CVE-2021-0318 CVE-2021-0318: In appendEventsToCacheLocked of SensorEventConnection
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-47551 kernel: drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again
bugzilla·2024-05-27·CVSS 6.5
CVE-2021-47551 [MEDIUM] CVE-2021-47551 kernel: drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again
CVE-2021-47551 kernel: drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again
The Linux kernel CVE team has assigned CVE-2021-47551 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052442-CVE-2021-47551-0318@gregkh/T
Discussion:
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2021-47551 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
Bugzilla
CVE-2020-10770 keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
bugzilla·2020-06-11·CVSS 5.3
CVE-2020-10770 [MEDIUM] CVE-2020-10770 keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
CVE-2020-10770 keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
The "request_uri" is an optional parameter in the OIDC Authentication Request that allows to specify an external URI where the Request object may be found. As the Identity Provider is supposed to request the external Request object, this parameter can be easily used to launch a SSRF attack against the IdP.
https://issues.redhat.com/browse/KEYCLOAK-14019
Discussion:
Acknowledgments:
Name: Lauritz Holtmann (@_lauritz_ ) (Chair for Network and Data Security at Ruhr University Bochum)
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4 for RHEL 6
Via RHSA-2021:0318 https://access.redhat.com/errata/RHSA-2021:0318
---
This issue has been address
2021-01-11
Published