CVE-2021-0308: High severity Google Android vulnerability
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158063095.
Other sources
The potential out of bounds write in ReadLogicalParts of basicmbr.cc due to missing bounds check in gdisk utility. Exploitation requires the use of a malicious storage (such as: USB) device that could cause a crash and possibly allows local privilege escalation.
References: https://packetstormsecurity.com/files/165869/USN-5262-1 https://sourceforge.net/p/gptfdisk/code/ci/f523bbc0c2437fe259aa3aff5e819e24101aee29
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0308?
CVE-2021-0308 is classified as a high-severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2021-0308?
To fix CVE-2021-0308, apply the latest security patches provided by Google for affected versions of Android.
Which versions of Android are affected by CVE-2021-0308?
CVE-2021-0308 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
Can CVE-2021-0308 be exploited without user interaction?
Yes, CVE-2021-0308 can be exploited without any user interaction required.
What is the nature of the vulnerability in CVE-2021-0308?
CVE-2021-0308 involves a possible out-of-bounds write due to a missing bounds check in the ReadLogicalParts function.