CVE-2023-21166: Use After Free
Published Dec 4, 2023
·Updated
In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android
Google Android
Event History
Dec 4, 2023
CVE Published
via Android·12:00 AM
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-21166?
The severity of CVE-2023-21166 is high with a severity value of 7.
2
What software is affected by CVE-2023-21166?
CVE-2023-21166 affects Google Android.
3
How can I fix CVE-2023-21166?
To fix CVE-2023-21166, apply the security patch provided by Google for the affected Android versions.
4
Where can I find more information about CVE-2023-21166?
You can find more information about CVE-2023-21166 in the Android Security Bulletin for December 2023.