CVE-2021-0326

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-0326

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:1686

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-0326.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202102-25

OS impact

OSVersionStatusFixed in
arch archfixed2:2.9-8
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed2:2.9.0-17
debian debianbullseyefixed2:2.9.0-17
debian debianforkyfixed2:2.9.0-17
debian debiansidfixed2:2.9.0-17
debian debiantrixiefixed2:2.9.0-17

References

Verify integrity in audit chain (admin only). AS-IS.