CVE-2021-25491: Null Pointer Dereference
Published Oct 6, 2021
·Updated
A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.
Affected Software
4 affected components
Google Android=9.0
Google Android=10.0
Google Android=11.0
Samsung Exynos
Event History
Oct 6, 2021
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25491?
The severity of CVE-2021-25491 is medium, with a CVSS score of 4.4.
2
Which software versions are affected by CVE-2021-25491?
CVE-2021-25491 affects Google Android versions 9.0, 10.0, and 11.0.
3
How does CVE-2021-25491 exploit the vulnerability?
CVE-2021-25491 exploits the vulnerability by causing memory corruption through a NULL-pointer dereference.
4
Is Samsung Exynos affected by CVE-2021-25491?
No, Samsung Exynos is not vulnerable to CVE-2021-25491.
5
How can I mitigate the vulnerability in CVE-2021-25491?
To mitigate the vulnerability in CVE-2021-25491, update your Google Android device to SMR Oct-2021 Release 1 or a later version.