First published: Thu Mar 04 2021(Updated: )
Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 | |
Google Android | =11.0 | |
Samsung Exynos 9830 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25338 is a vulnerability that allows an attacker, given a compromised kernel, to write certain parts of the RKP EL2 memory region on Samsung mobile devices prior to SMR Mar-2021 Release 1.
CVE-2021-25338 has a severity rating of 5.2, which is considered medium.
Yes, Google Android 10.0 is affected by CVE-2021-25338.
Yes, Google Android 11.0 is affected by CVE-2021-25338.
No, the Samsung Exynos 9830 is not vulnerable to CVE-2021-25338.
To fix CVE-2021-25338, users should install the SMR Mar-2021 Release 1 security update provided by Samsung for their mobile devices.