CVE-2021-39793
Android
Published 16 Mar 2022 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 11 Apr 2022, with a remediation deadline of 2 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A
References
- source.android.com/security/bulletin/pixel/2022-03-01 · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-39793 · Third Party Advisory, US Government Resource