ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-9376
In Account of Account.java, there is a possible boot loop due to improper input validation.

In Account of Account.java, there is a possible boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android; Versions: Android-9, Android-8.0, Android-8.1; Android ID: A-129287265.

NVD description · AI analysis pending
5.5<1%
  • google android
CVE-2021-0316
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check.

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-168802990.

NVD description · AI analysis pending
9.8
group max
3%
  • google android
CVE-2020-10732
A flaw was found in the Linux kernel's implementation of Userspace core dumps.

A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.

NVD description · AI analysis pending
4.4<1%
  • linux linux kernel
  • linux leap
  • linux ubuntu linux
  • +1 more
CVE-2020-10766
A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD.

A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top of the existing SSBD switching. The highest threat from this vulnerability is to confidentiality.

NVD description · AI analysis pending
5.5<1%
  • linux linux kernel
CVE-2020-11126
Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv

Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

NVD description · AI analysis pending
9.1<1%
  • qualcomm apq8096au firmware
  • qualcomm aqt1000 firmware
  • qualcomm ar8031 firmware
  • +1 more
CVE-2020-11182
+2 in the same advisory: …11134 …11238
Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Con

Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

NVD description · AI analysis pending
9.8
group max
<1%
  • qualcomm aqt1000 firmware
  • qualcomm pm3003a firmware
  • qualcomm pm4125 firmware
  • +1 more
CVE-2020-11159
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdr

Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

NVD description · AI analysis pending
9.1
group max
<1%
  • qualcomm apq8009 firmware
  • qualcomm apq8017 firmware
  • qualcomm apq8053 firmware
  • +1 more
CVE-2020-11181
Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer received from HLOS in Snapdragon Compute, Snap

Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer received from HLOS in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

NVD description · AI analysis pending
7.8<1%
  • qualcomm pm3003a firmware
  • qualcomm pm8009 firmware
  • qualcomm pm8150a firmware
  • +1 more
CVE-2020-11220
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing th

While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

NVD description · AI analysis pending
6.4<1%
  • qualcomm aqt1000 firmware
  • qualcomm ar8035 firmware
  • qualcomm pm4125 firmware
  • +1 more
CVE-2020-11250
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Con

Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

NVD description · AI analysis pending
7.0<1%
  • qualcomm apq8009w firmware
  • qualcomm apq8017 firmware
  • qualcomm apq8053 firmware
  • +1 more
CVE-2020-11260
An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

NVD description · AI analysis pending
8.4<1%
  • qualcomm apq8017 firmware
  • qualcomm apq8053 firmware
  • qualcomm aqt1000 firmware
  • +1 more
CVE-2020-11261
Local Privilege Escalation via Memory Corruption in Qualcomm Snapdragon Chipsets

CVE-2020-11261 is an improper input validation flaw (CWE-20/CWE-787, resulting in memory corruption/out-of-bounds writes) in the memory-allocation handling of firmware across a wide range of Qualcomm Snapdragon chipsets. It is triggered when a user application requests a memory allocation of a huge size and the affected component fails to properly return an error; a local attacker — such as a malicious or compromised app already running on the device — can leverage this to escalate privileges. Successful exploitation yields elevated privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local attack vector, no user interaction required). Affected platforms span the Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables product lines, including widely deployed entry-level mobile SoCs and connectivity chips. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-12-01, confirming in-the-wild exploitation; it was quietly patched in Android security updates alongside related Arm and Qualcomm zero-days, no public PoC is known, and EPSS estimates a 1.8% probability of exploitation in the next 30 days.

Do: Apply updated Qualcomm firmware and driver packages per the vendor advisory, as required by CISA's KEV listing, and ensure Android devices receive the OEM security updates containing the fix. Inventory devices built on the listed chipsets (e.g., APQ8009, APQ8017, APQ8053, APQ8096AU) and confirm they run patched builds; there is no workaround beyond patching, since a local malicious app is sufficient to trigger the flaw.

7.82% KEV
  • Qualcomm APQ8009 firmware
  • Qualcomm APQ8009W firmware
  • Qualcomm APQ8017 firmware
  • +9 more
mass≈1 billion+ devices (affected Snapdragon SoC families ship in entry-level Android phones and IoT/automotive hardware at massive volume)
CVE-2021-0323
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

NVD description · AI analysis pending
Full article275 words · extracted from securityaffairs.com · click to collapse

Google released an Android security update that addressed tens of flaws, including a critical Android remote code execution vulnerability.

Google released an Android security update that addresses 43 flaws, including a critical remote code execution vulnerability in the Android System component tracked as CVE-2021-0316. Google addressed the flaws with the release of Security patch levels of 2021-01-05 or later.

“The most severe of these issues is a critical security vulnerability in the System component that could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.” reads Google’s January Android security bulletin.

The bulletin also fixed a critical DoS vulnerability, tracked as CVE-2021-0313, that affects the Framework. The flaw could be exploited by a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.

The above vulnerabilities affect Android versions 8.0, 8.1, 9, 10 and 11.

Source code patches for these vulnerabilities have been released to the Android Open Source Project (AOSP) repository.

Google also addressed other 2 critical flaws in the Qualcomm closed-source components tracked as CVE-2020-11134 and CVE-2020-11182.

Google also fixed the following high-severity vulnerabilities:

  • Framework: CVE-2021-0303, CVE-2021-0306, CVE-2021-0307,CVE-2021-0310, CVE-2021-0315, CVE-2021-0317, CVE-2021-0318, CVE-2021-0319, CVE-2021-0304, CVE-2021-0309, CVE-2021-0321, CVE-2021-0322, CVE-2019-9376;
  • Media Framework: CVE-2021-0311, CVE-2021-0312; CVE-2021-0308, CVE-2021-0320;
  • System: CVE-2020-0471;
  • Kernel components: CVE-2020-10732, CVE-2020-10766, CVE-2021-0323;
  • MediaTek components: CVE-2021-0301;
  • Qualcomm components: CVE-2020-11233, CVE-2020-11239, CVE-2020-11220, CVE-2020-11250, CVE-2020-11261, CVE-2020-11262;
  • Qualcomm closed-source components: CVE-2020-11126, CVE-2020-11126, CVE-2020-11159, CVE-2020-11181, CVE-2020-11235, CVE-2020-11238, CVE-2020-11241, CVE-2020-11260.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Google)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/113095/security/google-android-rce.html