First published: Fri Jan 07 2022(Updated: )
There is a Double free vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei HarmonyOS | <2.0 | |
Huawei EMUI | =11.0.0 | |
Huawei EMUI | =12.0.0 | |
Huawei Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-40038 is categorized as a critical vulnerability affecting service integrity in the AOD module.
To fix CVE-2021-40038, ensure that your Huawei device's software is updated to the latest version provided by Huawei.
CVE-2021-40038 affects Huawei devices running HarmonyOS up to version 2.0, EMUI 11.0.0, EMUI 12.0.0, and Magic UI 4.0.0.
The double free vulnerability in CVE-2021-40038 implies that memory can be improperly deallocated twice, potentially leading to service disruptions or exploitation.
Yes, a patch for CVE-2021-40038 has been released as part of the software updates for affected Huawei devices.