CVE-2021-25489

CVE Published 2021-10-06
Related CWE(s) CWE-20: Improper Input Validation, CWE-134: Use of Externally-Controlled Format String
Related Vendor(s) google
Related Product(s) android
Exploitation Reported (CISA KEV) 2023-06-29
CVSS 3 Base Score 3.3 (LOW)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References