{"id":"ASB-A-181660448","details":"In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-181660448","CVE-2021-0516"],"modified":"2026-04-30T15:48:46.890647Z","published":"2021-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-06-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/13c4cdae55e840a1a47e57e19bfa59135358b8ca"}],"affected":[{"package":{"name":"platform/external/wpa_supplicant_8","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.1:0"},{"fixed":"8.1:2021-06-01"}]}],"versions":["8.1"],"ecosystem_specific":{"types":["EoP"],"spl":"2021-06-01","vanir_signatures":[{"signature_version":"v1","id":"ASB-A-181660448-2883d2df","signature_type":"Line","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/61dece6d28bd084f0f1987cdbfff735901ecb11c","digest":{"threshold":0.9,"line_hashes":["271018181069020268075351506102187983107","268700010634199033158328312405380838829","329970341488664131972201553473184135355","190733282669035384697854612416322817722","128312418882450711487850140666863854913","2917010316292243618786757244431791290","41800503454006324207678608315450033307","22938884100498773189593958736268896412","184332446520627855974836001186859673773","41382533008751572981989992649789272845","330425334554713280711169901383246438630"]},"target":{"file":"src/p2p/p2p_pd.c"},"deprecated":false},{"signature_version":"v1","id":"ASB-A-181660448-4e054bbc","signature_type":"Function","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/61dece6d28bd084f0f1987cdbfff735901ecb11c","digest":{"function_hash":"296722937661991391403820521325526362841","length":15065},"target":{"file":"src/p2p/p2p_pd.c","function":"p2p_process_prov_disc_req"},"deprecated":false}],"fixes":["https://android.googlesource.com/platform/external/wpa_supplicant_8/+/61dece6d28bd084f0f1987cdbfff735901ecb11c"],"severity":"Critical"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-181660448.json"}},{"package":{"name":"platform/external/wpa_supplicant_8","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9:0"},{"fixed":"9:2021-06-01"}]}],"versions":["9"],"ecosystem_specific":{"types":["EoP"],"spl":"2021-06-01","vanir_signatures":[{"signature_version":"v1","id":"ASB-A-181660448-32cdd266","signature_type":"Function","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/b8acd2a860f5a82a501be188a6f86f985cde74c4","digest":{"function_hash":"296722937661991391403820521325526362841","length":15065},"target":{"file":"src/p2p/p2p_pd.c","function":"p2p_process_prov_disc_req"},"deprecated":false},{"signature_version":"v1","id":"ASB-A-181660448-7c4c64ab","signature_type":"Line","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/b8acd2a860f5a82a501be188a6f86f985cde74c4","digest":{"threshold":0.9,"line_hashes":["271018181069020268075351506102187983107","268700010634199033158328312405380838829","329970341488664131972201553473184135355","190733282669035384697854612416322817722","128312418882450711487850140666863854913","2917010316292243618786757244431791290","41800503454006324207678608315450033307","22938884100498773189593958736268896412","184332446520627855974836001186859673773","41382533008751572981989992649789272845","330425334554713280711169901383246438630"]},"target":{"file":"src/p2p/p2p_pd.c"},"deprecated":false}],"fixes":["https://android.googlesource.com/platform/external/wpa_supplicant_8/+/b8acd2a860f5a82a501be188a6f86f985cde74c4"],"severity":"Critical"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-181660448.json"}},{"package":{"name":"platform/external/wpa_supplicant_8","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2021-06-01"}]}],"versions":["10"],"ecosystem_specific":{"types":["EoP"],"spl":"2021-06-01","vanir_signatures":[{"signature_version":"v1","id":"ASB-A-181660448-524f82b1","signature_type":"Function","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/8b68d7983c6139cdc4f65ba14b4af5ef9e5c66b7","digest":{"function_hash":"296722937661991391403820521325526362841","length":15065},"target":{"file":"src/p2p/p2p_pd.c","function":"p2p_process_prov_disc_req"},"deprecated":false},{"signature_version":"v1","id":"ASB-A-181660448-d1d4e4e0","signature_type":"Line","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/8b68d7983c6139cdc4f65ba14b4af5ef9e5c66b7","digest":{"threshold":0.9,"line_hashes":["271018181069020268075351506102187983107","268700010634199033158328312405380838829","329970341488664131972201553473184135355","190733282669035384697854612416322817722","128312418882450711487850140666863854913","2917010316292243618786757244431791290","41800503454006324207678608315450033307","22938884100498773189593958736268896412","184332446520627855974836001186859673773","41382533008751572981989992649789272845","330425334554713280711169901383246438630"]},"target":{"file":"src/p2p/p2p_pd.c"},"deprecated":false}],"fixes":["https://android.googlesource.com/platform/external/wpa_supplicant_8/+/8b68d7983c6139cdc4f65ba14b4af5ef9e5c66b7"],"severity":"Critical"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-181660448.json"}},{"package":{"name":"platform/external/wpa_supplicant_8","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-06-01"}]}],"versions":["11"],"ecosystem_specific":{"types":["EoP"],"spl":"2021-06-01","vanir_signatures":[{"signature_version":"v1","id":"ASB-A-181660448-5234699a","signature_type":"Function","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/838e6fd132c114d964eb8b589166a1defe8e6729","digest":{"function_hash":"296722937661991391403820521325526362841","length":15065},"target":{"file":"src/p2p/p2p_pd.c","function":"p2p_process_prov_disc_req"},"deprecated":false},{"signature_version":"v1","id":"ASB-A-181660448-58cb4c14","signature_type":"Line","source":"https://android.googlesource.com/platform/external/wpa_supplicant_8/+/838e6fd132c114d964eb8b589166a1defe8e6729","digest":{"threshold":0.9,"line_hashes":["271018181069020268075351506102187983107","268700010634199033158328312405380838829","329970341488664131972201553473184135355","190733282669035384697854612416322817722","128312418882450711487850140666863854913","2917010316292243618786757244431791290","41800503454006324207678608315450033307","22938884100498773189593958736268896412","184332446520627855974836001186859673773","41382533008751572981989992649789272845","330425334554713280711169901383246438630"]},"target":{"file":"src/p2p/p2p_pd.c"},"deprecated":false}],"fixes":["https://android.googlesource.com/platform/external/wpa_supplicant_8/+/838e6fd132c114d964eb8b589166a1defe8e6729"],"severity":"Critical"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-181660448.json"}}],"schema_version":"1.7.5"}