CVE-2021-25477: Double Free
Published Oct 6, 2021
·Updated
An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.
Affected Software
7 affected components
Google Android=9.0
Google Android=10.0
Google Android=11.0
MediaTek Mt6762
MediaTek Mt6765
MediaTek Mt6853
Google Android
Event History
Oct 6, 2021
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Apr 4, 2022
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-25477?
CVE-2021-25477 has a high severity rating due to its potential to cause modem crashes and remote denial of service.
2
How do I fix CVE-2021-25477?
To fix CVE-2021-25477, users should update their Android devices to a version released after the October 2021 security patch.
3
Which Android versions are affected by CVE-2021-25477?
CVE-2021-25477 affects Android versions 9.0, 10.0, and 11.0.
4
What are the consequences of CVE-2021-25477?
The consequences of CVE-2021-25477 include a potential remote denial of service that can disrupt device functionality.
5
Is CVE-2021-25477 specific to MediaTek devices?
CVE-2021-25477 is related to improper error handling in the Mediatek RRC Protocol stack but affects specific versions of Android on MediaTek chipsets.