CVE-2021-0895
Description
In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672003.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Out-of-bounds write in MediaTek apusys driver allows local escalation of privilege with System execution privileges.
Vulnerability
In the apusys driver on MediaTek chipsets, a missing bounds check leads to an out-of-bounds write. This vulnerability is present in the apusys component and requires System execution privileges to exploit. The affected versions include all chipsets using the apusys driver, as listed in the December 2021 MediaTek Product Security Bulletin [1]. The patch ID is ALPS05672107.
Exploitation
An attacker with System execution privileges can trigger the out-of-bounds write without any user interaction. The exact exploitation steps are not publicly detailed, but the missing bounds check allows writing beyond the allocated buffer, potentially corrupting kernel memory.
Impact
Successful exploitation leads to local escalation of privilege. Although the attacker already requires System execution privileges, the out-of-bounds write can be used to gain further control over the system, such as executing arbitrary code with elevated permissions or bypassing security mechanisms.
Mitigation
MediaTek released a patch (ALPS05672107) in the December 2021 Product Security Bulletin [1]. Device OEMs were notified at least two months before publication. Users should apply the security update from their device manufacturer. No workarounds are documented, and this CVE is not listed in the Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- apusys/apusysdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- corp.mediatek.com/product-security-bulletin/December-2021mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.