VYPR
Unrated severityNVD Advisory· Published Dec 17, 2021· Updated Aug 3, 2024

CVE-2021-0903

CVE-2021-0903

Description

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05656488.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing bounds check in MediaTek apusys driver allows a local out-of-bounds write, leading to escalation of privilege to System.

Vulnerability

CVE-2021-0903 is an out-of-bounds write vulnerability in the apusys driver of MediaTek chipsets. It is caused by a missing bounds check when handling certain operations. Affected chipsets include MT6570, MT6580, MT6735, MT6737, MT6739, MT6750, MT6750S, MT6753, MT6755, MT6755S, MT6757, MT6757C, MT6757CD, MT6757CH, MT6758, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6797, MT6799, MT6833, and others listed in the December 2021 MediaTek Product Security Bulletin [1]. The vulnerability is addressed by patch ALPS05672107.

Exploitation

Exploitation requires System execution privileges. No user interaction is needed, and no additional execution privileges beyond the initial System level are required. An attacker with System access can trigger the out-of-bounds write to corrupt kernel memory or other critical structures.

Impact

Successful exploitation allows an attacker with System privileges to escalate their privileges further within the kernel context, potentially achieving arbitrary code execution at the highest privilege level System. This can lead to full compromise of the device's confidentiality, integrity, and availability.

Mitigation

The fix was included in the December 2021 MediaTek Product Security Bulletin [1]. Device OEMs are expected to apply patch ALPS05672107. Users should install the latest security updates from their device manufacturer. No workaround is available, and the issue is not listed in CISA's Known Exploited Vulnerabilities (KEV) as of the publication date.

References
  1. December 2021

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.