QID 610325

Date Published: 2021-03-24

QID 610325: Google Android March 2021 Security Patch Missing for Samsung

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2020-11170, CVE-2020-11163, CVE-2020-11272, CVE-2021-0397,CVE-2020-11271, CVE-2020-11282, CVE-2017-18509, CVE-2020-11286, CVE-2020-11177, CVE-2020-11187, CVE-2020-11253, CVE-2020-11281, CVE-2020-11296, CVE-2020-11269, CVE-2020-11275, CVE-2020-11280, CVE-2020-11287, CVE-2020-11276, CVE-2020-11270, CVE-2020-11297, CVE-2020-11278, CVE-2021-0395, CVE-2021-0391, CVE-2021-0398, CVE-2017-14491, CVE-2021-0393, CVE-2021-0396, CVE-2021-0390, CVE-2021-0392, CVE-2021-0394

Affected Products :
Galaxy Fold, Galaxy Fold 5G, Galaxy Z Fold2, Galaxy Z Fold2 5G, Galaxy Z Flip, Galaxy Z Flip 5G
Galaxy S9, Galaxy S9+, Galaxy S10, Galaxy S10+, Galaxy S10e, Galaxy S10 5G, Galaxy S10 Lite, Galaxy S20, Galaxy S20 5G, Galaxy S20+, Galaxy S20+ 5G, Galaxy S20 Ultra, Galaxy S20 Ultra 5G, Galaxy S20 FE, Galaxy S20 FE 5G
Galaxy Note9, Galaxy Note10, Galaxy Note10 5G, Galaxy Note10+, Galaxy Note10+ 5G, Galaxy Note10 Lite, Galaxy Note20, Galaxy Note20 5G, Galaxy Note20 Ultra, Galaxy Note20 Ultra 5G
Enterprise Models: Galaxy A8 (2018), Galaxy A50, Galaxy XCover4s, Galaxy XCover FieldPro, Galaxy XCover Pro

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to Samsung Security advisory SMR-March-2021 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-March-2021 Android URL Logo security.samsungmobile.com/securityUpdate.smsb