CVE-2021-0670: Use After Free
Published Nov 18, 2021
·Updated
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05654663; Issue ID: ALPS05654663.
Affected Software
15 affected components
Google Android=10.0
Google Android=11.0
MediaTek Mt6853
MediaTek Mt6853t
MediaTek Mt6873
MediaTek Mt6875
MediaTek Mt6877
MediaTek Mt6883
MediaTek Mt6885
MediaTek Mt6889
MediaTek Mt6891
MediaTek Mt6893
MediaTek Mt8195
MediaTek Mt8791
MediaTek Mt8797
Event History
Nov 18, 2021
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-0670?
CVE-2021-0670 has a severity level that allows for local escalation of privilege but requires System execution privileges.
2
How do I fix CVE-2021-0670?
To fix CVE-2021-0670, apply the patch identified as ALPS05654663.
3
Who is affected by CVE-2021-0670?
CVE-2021-0670 affects devices running Android versions 10.0 and 11.0.
4
Is user interaction required to exploit CVE-2021-0670?
No, user interaction is not required for exploitation of CVE-2021-0670.
5
What type of vulnerability is CVE-2021-0670?
CVE-2021-0670 is classified as a memory corruption vulnerability due to a use after free.