Description Preview
A use-after-free vulnerability was discovered in the acc_read function of f_accessory.c in the Android kernel. This vulnerability could allow a local attacker to corrupt memory, potentially leading to local privilege escalation. The issue occurs when previously freed memory is accessed, creating a condition where memory corruption can occur. No additional execution privileges are required for exploitation, and user interaction is not needed.
Overview
CVE-2021-0936 is a use-after-free vulnerability (CWE-416) in the Android kernel's USB accessory functionality. The vulnerable code exists in the acc_read function within f_accessory.c. When exploited, an attacker can cause memory corruption by accessing memory after it has been freed, which could lead to privilege escalation on the affected device. This vulnerability is particularly concerning because it requires no user interaction and can be exploited by a local attacker without needing additional execution privileges. The issue affects various Android devices and was addressed in the October 2021 Pixel security update.
Remediation
To mitigate this vulnerability, users should:
- Update affected Android devices to the latest available security patch level, specifically the October 2021 security update or later.
- For Pixel device owners, ensure the October 2021 Pixel security update is installed.
- For other Android device manufacturers, check with the vendor for availability of security patches addressing this issue.
- System administrators managing Android enterprise deployments should prioritize this update, as local privilege escalation vulnerabilities can be leveraged in multi-stage attacks.
- If updates are not available, consider limiting physical access to affected devices and restricting installation of untrusted applications.
References
- Android Security Bulletin - Pixel Update Bulletin - October 2021: https://source.android.com/security/bulletin/pixel/2021-10-01
- CWE-416: Use After Free: https://cwe.mitre.org/data/definitions/416.html
- Android Security Vulnerability ID: A-173789633
- The issue was also addressed in the upstream Linux kernel
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- ManufacturingManufacturing
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade