Memory Management Driver Flaw in MediaTek Products
CVE-2021-0424

5.5MEDIUM

What is CVE-2021-0424?

A flaw in the memory management driver associated with MediaTek products allows a possible system crash due to a missing bounds check. This vulnerability can lead to a local denial of service, enabling an attacker to disrupt system operations without the need for additional execution privileges. User interaction is not required for exploitation, making this issue particularly concerning for affected users. Affected users are encouraged to apply the provided patches from MediaTek to mitigate the risk.

Affected Version(s)

MT6580, MT6582E, MT6582H, MT6582T, MT6582W, MT6582_90, MT6589, MT6589TD, MT6592E, MT6592H, MT6592T, MT6592W, MT6592_90, MT6595, MT6731, MT6732, MT6735, MT6737, MT6739, MT6750, MT6750S, MT6752, MT6753, MT6755, MT6755S, MT6757, MT6757C, MT6757CD, MT6757CH, MT6758, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6785, MT6795, MT6797, MT6799, MT6833, MT6853, MT6853T, MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893 Android 10.0, 11.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.