CVE-2021-1013
published 2021-12-15CVE-2021-1013: In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.11%
1.5th percentile
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186404356
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 12:0 < 12:2021-12-01 | 12:2021-12-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-325x-phgw-f22w: In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService
ghsa_unreviewed·2021-12-16
CVE-2021-1013 [MEDIUM] CWE-203 GHSA-325x-phgw-f22w: In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186404356
OSV
CVE-2021-1013: In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService
osv·2021-12-01
CVE-2021-1013 CVE-2021-1013: In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Red Hat
kernel: iio: accel: kxcjk-1013: Fix possible memory leak in probe and remove
vendor_redhat·2024-05-24·CVSS 5.5
CVE-2021-47499 [MEDIUM] CWE-401 kernel: iio: accel: kxcjk-1013: Fix possible memory leak in probe and remove
kernel: iio: accel: kxcjk-1013: Fix possible memory leak in probe and remove
In the Linux kernel, the following vulnerability has been resolved:
iio: accel: kxcjk-1013: Fix possible memory leak in probe and remove
When ACPI type is ACPI_SMO8500, the data->dready_trig will not be set, the
memory allocated by iio_triggered_buffer_setup() will not be freed, and cause
memory leak as follows:
unreferenced object 0xffff888009551400 (size 512):
comm "i2c-SMO8500-125", pid 911, jiffies 4294911787 (age 83.852s)
hex dump (first 32 bytes):
02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 20 e2 e5 c0 ff ff ff ff ........ .......
backtrace:
[] kmem_cache_alloc_trace+0x16d/0x360
[] iio_kfifo_allocate+0x41/0x130 [kfifo_buf]
[] iio_triggered_buffer_setup_ext+0x2c/0
No detection rules found.
No public exploits indexed.
2021-12-15
Published