CVE-2021-0607 is a missing bounds check vulnerability in the Android kernel's iaxxx-codec.c, specifically within the iaxxx_calc_i2s_div function, which could lead to a hardware port write with user-controlled data. This flaw allows for local escalation of privilege without requiring additional execution privileges or user interaction. Rated with a CVSS score of 7.8 (HIGH), the vulnerability has a low attack complexity and can result in high impacts to confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and with no public exploit code available (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, including an article from Threatpost.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.