CVE-2023-21218: Critical severity android vulnerability
Published Dec 4, 2023
·Updated
In PMRChangeSparseMemOSMem of physmemosmemlinux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android
Google Android
Event History
Dec 4, 2023
CVE Published
via Android·12:00 AM
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-21218?
CVE-2023-21218 has a high severity level with a severity value of 7.
2
What software is affected by CVE-2023-21218?
CVE-2023-21218 affects the Google Android operating system.
3
How can I fix CVE-2023-21218?
To fix CVE-2023-21218, it is recommended to install the security patches provided by Google for the Android operating system.
4
Where can I find more information about CVE-2023-21218?
More information about CVE-2023-21218 can be found in the Android Security Bulletin for December 2023.
5
Are there any references related to CVE-2023-21218?
Yes, you can find references to CVE-2023-21218 in the Android Security Bulletin for December 2023.