CVE-2023-21215
published 2023-12-04CVE-2023-21215: In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.41%
33.5th percentile
In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| chrome_chrome | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-21215
vendor_chrome·2024-02-01·CVSS 9.8
CVE-2023-21215 [CRITICAL] Long Term Support Channel Update for ChromeOS: CVE-2023-21215
Long Term Support Channel Update for ChromeOS
CVE-2023-21215
Android
CVE-2023-21215: PowerVR-GPU
vendor_android·2023-12-01·CVSS 9.8
CVE-2023-21215 [CRITICAL] CVE-2023-21215: PowerVR-GPU
Android Security Bulletin 2023-12-01
CVE: CVE-2023-21215
Severity: HIGH
Component: PowerVR-GPU
References: A-291982610
*
OSV
CVE-2023-21215: In DevmemIntAcquireRemoteCtx of devicemem_server
osv·2023-12-01
CVE-2023-21215 CVE-2023-21215: In DevmemIntAcquireRemoteCtx of devicemem_server
In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible
arbitrary code execution due to a race condition. This could lead to local
escalation of privilege in the kernel with no additional execution
privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-04
Published