QID 610323

Date Published: 2021-03-24

QID 610323: Google Android March 2021 Security Patch Missing for LGE

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2021-0397 , CVE-2020-11272 , CVE-2020-11163 , CVE-2020-11170,CVE-2021-0395 , CVE-2021-0391 , CVE-2021-0398 , CVE-2017-14491 , CVE-2021-0393 , CVE-2021-0396 , CVE-2021-0390 , CVE-2021-0392 , CVE-2021-0394 , CVE-2017-18509 , CVE-2020-11271 , CVE-2020-11277 , CVE-2020-11282 , CVE-2020-11286 , CVE-2020-11297 , CVE-2020-11177 , CVE-2020-11180 , CVE-2020-11187 , CVE-2020-11253 , CVE-2020-11269 , CVE2020-11270 , CVE-2020-11275 , CVE-2020-11276 , CVE-2020-11278 , CVE-2020-11280 , CVE-2020-11281 , CVE-2020-11287 , CVE-2020-11296

Affected Products :
G series (G5, G6, G7, G8), V series(V10, V20, V30, V35, V40, V50) , Q Series(Q6, Q8) , X Series(X300, X400, X500, X cam), CV Series(CV1, CV3, CV5, CV7, CV1S, CV7AS), MH(K40, K50, Q60, Q70)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to LGE Security advisory SMR-March-2021 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-March-2021 Android URL Logo lgsecurity.lge.com/security_updates_mobile.html