Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
| Software | From | Fixed in |
|---|---|---|
| google / android | 10.0 | 10.0.x |
| google / android | 11.0 | 11.0.x |