CVE-2021-25488: Medium severity android vulnerability
Published Oct 6, 2021
·Updated
Lack of boundary checking of a buffer in recvdata() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.
Affected Software
5 affected components
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android=11.0
Samsung Exynos
Event History
Oct 6, 2021
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25488?
The severity of CVE-2021-25488 is medium with a severity value of 5.5.
2
Which software versions are affected by CVE-2021-25488?
CVE-2021-25488 affects Google Android versions 8.1, 9.0, 10.0, and 11.0.
3
What is the vulnerability description of CVE-2021-25488?
CVE-2021-25488 is a vulnerability that allows out-of-bounds read due to lack of boundary checking in the recv_data() function of the modem interface driver prior to SMR Oct-2021 Release 1.
4
Is Samsung Exynos vulnerable to CVE-2021-25488?
No, Samsung Exynos is not vulnerable to CVE-2021-25488.
5
How can I fix CVE-2021-25488?
To fix CVE-2021-25488, it is recommended to apply the SMR Oct-2021 Release 1 security update provided by Google for affected Android versions.