CVE-2021-0338

MEDIUM

Android 10-11 - Denial of Service via SystemSettingsValidators UI Settings

Title source: llm
STIX 2.1

Description

In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-156260178

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://source.android.com/security/bulletin/2021-02-01

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 4.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (2)
google/android 10.0
google/android 11.0
Published Feb 10, 2021
Tracked Since Feb 18, 2026