CVE-2021-0967: Critical severity Google Android vulnerability
Published Dec 6, 2021
·Updated
In vorbisbookdecodevset of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-199065614
Affected Software
5 affected components
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android=12.0
Google Android
Remediation
Patch Available
Event History
Dec 6, 2021
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Dec 15, 2021
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-0967?
CVE-2021-0967 has a moderate severity level due to the potential for remote information disclosure.
2
How do I fix CVE-2021-0967?
To fix CVE-2021-0967, update your Android device to the latest security patch provided by Google.
3
Which Android versions are affected by CVE-2021-0967?
CVE-2021-0967 affects Android versions 9.0, 10.0, 11.0, and 12.0.
4
What kind of vulnerability is CVE-2021-0967?
CVE-2021-0967 is classified as an out-of-bounds write vulnerability.
5
Is user interaction required for CVE-2021-0967 exploitation?
Yes, user interaction is required to exploit CVE-2021-0967.