CVE Vulnerabilities

CVE-2021-37120

Double Free

Published: Jan 03, 2022 | Modified: Jan 13, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel crash or privilege escalation.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Emui Huawei 10.1.0 (including) 10.1.0 (including)
Emui Huawei 10.1.1 (including) 10.1.1 (including)
Magic_ui Huawei 3.1.0 (including) 3.1.0 (including)
Magic_ui Huawei 3.1.1 (including) 3.1.1 (including)

Potential Mitigations

References