CVE-2021-0326
In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525
- Affected products
- Android, Astra Linux, Centos, Linuxmint, Red Hat, Rocky Linux, Suse, Ubuntu
- Google Android
- = 8.1, 9.0, 10.0, 11.0
- CVSS 2.0
- 7.9 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 4.9% (92th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2021-02-10
CVE-2021-0326 at NVD
6 known exploits for CVE-2021-0326
Proof-of-concept code and exploit modules indexed by Sploitus