First published: Fri Jan 07 2022(Updated: )
There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
HarmonyOS | <2.0 | |
EMUI 5.0 | =11.0.0 | |
EMUI 5.0 | =12.0.0 | |
Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40009 is considered to have a high severity due to its potential impact on service integrity.
To mitigate CVE-2021-40009, users should update their Huawei devices to the latest software versions provided by Huawei.
CVE-2021-40009 affects Huawei devices running HarmonyOS 2.0 and EMUI versions 11.0.0 and 12.0.0, as well as Magic UI 4.0.0.
CVE-2021-40009 does not specifically indicate the potential for remote code execution, but it may allow for exploitation that affects device functionality.
Yes, a patch for CVE-2021-40009 is available through software updates from Huawei.