CVE-2021-0667: Use After Free
Published Nov 18, 2021
·Updated
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05670581; Issue ID: ALPS05670581.
Affected Software
20 affected components
Google Android=10.0
Google Android=11.0
MediaTek Mt6873
MediaTek Mt6875
MediaTek Mt6877
MediaTek Mt6883
MediaTek Mt6885
MediaTek Mt6889
MediaTek Mt6891
MediaTek Mt6893
MediaTek Mt9636
MediaTek Mt9638
MediaTek Mt9639
MediaTek Mt9650
MediaTek Mt9652
MediaTek Mt9669
MediaTek Mt9686
MediaTek Mt9970
MediaTek Mt9980
MediaTek Mt9981
Event History
Nov 18, 2021
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-0667?
CVE-2021-0667 is a vulnerability in the apusys component that can lead to local escalation of privilege with System execution privileges needed.
2
How severe is CVE-2021-0667?
CVE-2021-0667 has a severity rating of 6.7 (medium).
3
Which software versions are affected by CVE-2021-0667?
CVE-2021-0667 affects Google Android 10.0 and 11.0.
4
Is Mediatek Mt6873 affected by CVE-2021-0667?
No, Mediatek Mt6873 is not affected by CVE-2021-0667.
5
How can CVE-2021-0667 be patched?
The patch ID for CVE-2021-0667 is ALPS05670581. Please refer to the official Mediatek Product Security Bulletin for instructions on applying the patch.