CVE-2023-21216: Use After Free
Published Dec 4, 2023
·Updated
In PMRChangeSparseMemOSMem of physmemosmemlinux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android
Google Android
Event History
Dec 4, 2023
CVE Published
via Android·12:00 AM
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-21216?
CVE-2023-21216 is a vulnerability that allows elevation of privilege.
2
Which software is affected by CVE-2023-21216?
Google Android is the affected software.
3
What is the severity of CVE-2023-21216?
CVE-2023-21216 is classified as high severity with a severity value of 7.
4
How can I fix CVE-2023-21216?
To fix CVE-2023-21216, apply the latest security patch provided by Google for the affected Android version.
5
Where can I find more information about CVE-2023-21216?
You can find more information about CVE-2023-21216 in the Android Security Bulletin for the release on December 1, 2023.