CVE-2021-0326: High severity android vulnerability
In p2pcopyclientinfo of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-0326?
CVE-2021-0326 is a vulnerability in the p2p_copy_client_info function of p2p.c that allows for a possible out of bounds write due to a missing bounds check.
What is the severity of CVE-2021-0326?
The severity of CVE-2021-0326 is critical with a CVSSv3 score of 7.5.
Which software versions are affected by CVE-2021-0326?
The affected software versions include wpa 2:2.6-15ubuntu2.7, 2:2.9-1ubuntu4.2, 2:2.9-1ubuntu8.1, 2.1-0ubuntu1.7+, 2:2.9.0-17, and 2.4-0ubuntu6.7.
How can I fix CVE-2021-0326?
To fix CVE-2021-0326, update the affected software to the recommended versions: 2:2.6-15ubuntu2.7, 2:2.9-1ubuntu4.2, 2:2.9-1ubuntu8.1, 2.1-0ubuntu1.7+, 2:2.9.0-17, or 2.4-0ubuntu6.7.
Is user interaction required for exploitation of CVE-2021-0326?
No, user interaction is not needed for exploitation of CVE-2021-0326.