First published: Mon Dec 04 2023(Updated: )
In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21401 is a vulnerability that leads to elevation of privilege in Google Android.
CVE-2023-21401 has a severity rating of high (7 out of 10).
CVE-2023-21401 affects Google Android by allowing an attacker to elevate their privileges.
To fix CVE-2023-21401, it is recommended to apply the security patch provided by Google for the affected version of Android.
You can find more information about CVE-2023-21401 and the security bulletin on the Android Security Bulletin page (refer to the provided reference link).