QID 610385

Date Published: 2021-12-28

QID 610385: Google Android December 2021 Security Patch Missing for Samsung

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2021-1924, CVE-2021-1975, CVE-2021-0967, CVE-2021-0968, CVE-2021-0956,CVE-2021-1979, CVE-2021-30255, CVE-2021-1921, CVE-2021-1973, CVE-2021-0929, CVE-2021-0920, CVE-2021-30284, CVE-2021-30254, CVE-2021-1982, CVE-2021-1981, CVE-2021-1048, CVE-2021-0955, CVE-2021-0970, CVE-2021-0704, CVE-2021-0967,CVE-2021-0964, CVE-2021-0953, CVE-2021-0954, CVE-2021-0963, CVE-2021-0965, CVE-2021-0952, CVE-2021-0966,CVE-2021-0958, CVE-2021-0969, CVE-2021-1903

Affected Products :
Galaxy Fold, Galaxy Fold 5G, Galaxy Z Fold2, Galaxy Z Fold2 5G, Galaxy Z Fold3 5G, Galaxy Z Flip, Galaxy Z Flip 5G, Galaxy Z Flip3 5G Galaxy S10, Galaxy S10+, Galaxy S10e, Galaxy S10 5G, Galaxy S10 Lite Galaxy S20, Galaxy S20 5G, Galaxy S20+, Galaxy S20+ 5G, Galaxy S20 Ultra, Galaxy S20 Ultra 5G, Galaxy S20 FE, Galaxy S20 FE 5G, Galaxy S21 5G, Galaxy S21+ 5G, Galaxy S21 Ultra 5G Galaxy Note10, Galaxy Note10 5G, Galaxy Note10+, Galaxy Note10+ 5G, Galaxy Note10 Lite, Galaxy Note20, Galaxy Note20 5G, Galaxy Note20 Ultra, Galaxy Note20 Ultra 5G Galaxy A52, Galaxy A52 5G, Galaxy A52s 5G Enterprise Models: Galaxy A50, Galaxy XCover4s, Galaxy Xcover FieldPro, Galaxy Xcover Pro, Galaxy Xcover5

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to Samsung Security advisory SMR-December-2021 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-December-2021 Android URL Logo security.samsungmobile.com/securityUpdate.smsb