CVE-2021-1977: Critical severity Google Android vulnerability
Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1977?
CVE-2021-1977 is rated as a high severity vulnerability due to its potential to cause buffer over-read and exploitation risks.
How do I fix CVE-2021-1977?
The fix for CVE-2021-1977 involves applying the latest firmware updates or patches provided by Qualcomm or your device manufacturer.
Which devices are affected by CVE-2021-1977?
CVE-2021-1977 affects various Snapdragon processors, including but not limited to APQ8009, APQ8017, APQ8053, and several others listed in the advisory.
What type of vulnerability is CVE-2021-1977?
CVE-2021-1977 is classified as a buffer over-read vulnerability due to improper validation of frame length.
Can CVE-2021-1977 be exploited remotely?
Yes, CVE-2021-1977 may potentially be exploitable remotely, increasing the risk for affected devices.