VYPR
Unrated severityNVD Advisory· Published Dec 17, 2021· Updated Aug 3, 2024

CVE-2021-0895

CVE-2021-0895

Description

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672003.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Out-of-bounds write in MediaTek apusys driver allows local escalation of privilege with System execution privileges.

Vulnerability

In the apusys driver on MediaTek chipsets, a missing bounds check leads to an out-of-bounds write. This vulnerability is present in the apusys component and requires System execution privileges to exploit. The affected versions include all chipsets using the apusys driver, as listed in the December 2021 MediaTek Product Security Bulletin [1]. The patch ID is ALPS05672107.

Exploitation

An attacker with System execution privileges can trigger the out-of-bounds write without any user interaction. The exact exploitation steps are not publicly detailed, but the missing bounds check allows writing beyond the allocated buffer, potentially corrupting kernel memory.

Impact

Successful exploitation leads to local escalation of privilege. Although the attacker already requires System execution privileges, the out-of-bounds write can be used to gain further control over the system, such as executing arbitrary code with elevated permissions or bypassing security mechanisms.

Mitigation

MediaTek released a patch (ALPS05672107) in the December 2021 Product Security Bulletin [1]. Device OEMs were notified at least two months before publication. Users should apply the security update from their device manufacturer. No workarounds are documented, and this CVE is not listed in the Known Exploited Vulnerabilities (KEV) catalog.

References
  1. December 2021

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.