QID 610320

Date Published: 2021-03-24

QID 610320: Google Android February 2021 Security Patch Missing for Samsung

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2021-0325, CVE-2021-0326, CVE-2020-11182, CVE-2020-11134,CVE-2021-0325, CVE-2020-10732, CVE-2020-11126, CVE-2020-11159, CVE-2020-11233, CVE-2020-11235, CVE-2020-11238, CVE-2020-11239, CVE-2020-11240, CVE-2020-11241, CVE-2020-11250, CVE-2020-11261, CVE-2020-11262, CVE-2021-0301, CVE-2021-0302, CVE-2021-0305, CVE-2021-0314, CVE-2021-0327, CVE-2021-0328, CVE-2021-0329, CVE-2021-0330, CVE-2021-0331, CVE-2021-0332, CVE-2021-0333, CVE-2021-0334, CVE-2021-0335, CVE-2021-0336, CVE-2021-0337, CVE-2021-0338, CVE-2021-0339, CVE-2021-0340, CVE-2021-0341

Affected Products :
Galaxy Fold, Galaxy Fold 5G, Galaxy Z Fold2, Galaxy Z Fold2 5G, Galaxy Z Flip, Galaxy Z Flip 5G
Galaxy S9, Galaxy S9+, Galaxy S10, Galaxy S10+, Galaxy S10e, Galaxy S10 5G, Galaxy S10 Lite, Galaxy S20, Galaxy S20 5G, Galaxy S20+, Galaxy S20+ 5G, Galaxy S20 Ultra, Galaxy S20 Ultra 5G, Galaxy S20 FE, Galaxy S20 FE 5G
Galaxy Note9, Galaxy Note10, Galaxy Note10 5G, Galaxy Note10+, Galaxy Note10+ 5G, Galaxy Note10 Lite, Galaxy Note20, Galaxy Note20 5G, Galaxy Note20 Ultra, Galaxy Note20 Ultra 5G
Enterprise Models: Galaxy A8 (2018), Galaxy A50, Galaxy XCover4s, Galaxy XCover FieldPro, Galaxy XCover Pro

On successful exploitation it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Samsung Security advisory SMR-February-2021 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-February-2021 Android URL Logo security.samsungmobile.com/securityUpdate.smsb