{"api_version":"1","generated_at":"2026-07-24T19:11:37+00:00","cve":"CVE-2021-36994","urls":{"html":"https://cve.report/CVE-2021-36994","api":"https://cve.report/api/cve/CVE-2021-36994.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-36994","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-36994"},"summary":{"title":"CVE-2021-36994","description":"There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist.","state":"PUBLIC","assigner":"psirt@huawei.com","published_at":"2021-10-28 13:15:00","updated_at":"2021-11-01 23:07:00"},"problem_types":["CWE-362"],"metrics":[],"references":[{"url":"https://consumer.huawei.com/en/support/bulletin/2021/7/","name":"https://consumer.huawei.com/en/support/bulletin/2021/7/","refsource":"MISC","tags":[],"title":"Huawei EMUI/Magic UI security updates July 2021","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-36994","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36994","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"36994","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"emui","cpe6":"10.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"36994","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"emui","cpe6":"11.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"36994","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"magic_ui","cpe6":"3.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"36994","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"magic_ui","cpe6":"4.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@huawei.com","ID":"CVE-2021-36994","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"EMUI","version":{"version_data":[{"version_affected":"=","version_value":"11.0.0"},{"version_affected":"=","version_value":"10.1.1"}]}},{"product_name":"Magic UI","version":{"version_data":[{"version_affected":"=","version_value":"4.0.0"},{"version_affected":"=","version_value":"3.1.1"}]}}]},"vendor_name":"Huawei"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Competitive Condition Vulnerability"}]}]},"references":{"reference_data":[{"url":"https://consumer.huawei.com/en/support/bulletin/2021/7/","refsource":"MISC","name":"https://consumer.huawei.com/en/support/bulletin/2021/7/"}]}},"nvd":{"publishedDate":"2021-10-28 13:15:00","lastModifiedDate":"2021-11-01 23:07:00","problem_types":["CWE-362"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:huawei:magic_ui:3.1.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:huawei:emui:10.1.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:huawei:magic_ui:4.0.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:huawei:emui:11.0.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"36994","Ordinal":"212575","Title":"CVE-2021-36994","CVE":"CVE-2021-36994","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"36994","Ordinal":"1","NoteData":"There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"36994","Ordinal":"2","NoteData":"2021-10-28","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"36994","Ordinal":"3","NoteData":"2021-10-28","Type":"Other","Title":"Modified"}]}}}