CVE-2023-21215: Race Condition
Published Dec 4, 2023
·Updated
In DevmemIntAcquireRemoteCtx of devicememserver.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android
Google Android
Event History
Dec 4, 2023
CVE Published
via Android·12:00 AM
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-21215?
The severity of CVE-2023-21215 is high.
2
Which software is affected by CVE-2023-21215?
CVE-2023-21215 affects Google Android.
3
How can I fix CVE-2023-21215?
To fix CVE-2023-21215, make sure to update your Google Android device to the latest security patch.
4
Where can I find more information about CVE-2023-21215?
You can find more information about CVE-2023-21215 on the official Android Security Bulletin for December 2023.