CVE-2021-0397: Double Free
Published Mar 1, 2021
·Updated
In sdpcopyrawdata of sdpdiscovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174052148
Affected Software
5 affected components
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android
Event History
Mar 1, 2021
CVE Published
via Android·12:00 AM
Mar 10, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-0397?
CVE-2021-0397 is rated as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2021-0397?
To mitigate CVE-2021-0397, update your Android device to the latest security patch provided by Google.
3
What systems are affected by CVE-2021-0397?
CVE-2021-0397 affects Android versions 8.1, 9.0, 10.0, and 11.0.
4
What type of vulnerability is CVE-2021-0397?
CVE-2021-0397 is a double free vulnerability which may lead to system compromise.
5
Does CVE-2021-0397 require user interaction for exploitation?
No, CVE-2021-0397 can be exploited without any user interaction.