peter bassill · operator
$ cve CVE-2021-39793 JSON

CVE-2021-39793 KEV

7.8
HIGH · CVSS 3.1 · EPSS 0.7% (pctl 51)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-02.

Description

In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.69% — more likely to be exploited than 51% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-05-02
Public exploitnone known
Published2022-03-16
Last modified2026-06-17

CISA KEV

NameGoogle Pixel Out-of-Bounds Write Vulnerability
Added2022-04-11
Due2022-05-02
Vendor / productGoogle / Pixel
Ransomware usenone reported

Affected (1)

VendorProduct
googleandroid

References

→ the Explorer  ·  watch your stack  ·  NVD