CVE-2021-0958
published 2021-12-15CVE-2021-0958: In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service…
PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.11%
1.4th percentile
In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-200041882
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 11:0 < 11:2021-12-01 | 11:2021-12-01 |
| platform | system_security | >= 12:0 < 12:2021-12-01 | 12:2021-12-01 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-0958: Android Security Bulletin 2021-12-01
CVE: CVE-2021-0958
Severity: MEDIUM
Type: DoS
Affected AOSP versions: 11, 12
References: A-200041882
vendor_android·2021-12-01·CVSS 4.4
CVE-2021-0958 [MEDIUM] CVE-2021-0958: Android Security Bulletin 2021-12-01
CVE: CVE-2021-0958
Severity: MEDIUM
Type: DoS
Affected AOSP versions: 11, 12
References: A-200041882
Android Security Bulletin 2021-12-01
CVE: CVE-2021-0958
Severity: MEDIUM
Type: DoS
Affected AOSP versions: 11, 12
References: A-200041882
GHSA
GHSA-56pm-22qm-mvhr: In update of km_compat
ghsa_unreviewed·2021-12-16
CVE-2021-0958 [MEDIUM] GHSA-56pm-22qm-mvhr: In update of km_compat
In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-200041882
OSV
CVE-2021-0958: In update of km_compat
osv·2021-12-01
CVE-2021-0958 CVE-2021-0958: In update of km_compat
In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published