Junglewise Threat Intelligence

CVE-2021-39793: Google Pixel Out-of-Bounds Write Vulnerability

CVE-2021-39793 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-04-11

Technologies: Android Pixel. Vendors: Google, Android.

Executive brief

An out-of-bounds write vulnerability exists in the kbase_jd_user_buf_pin_pages function of mali_kbase_mem.c in the Android kernel. A logic error allows for local escalation of privilege without requiring additional execution privileges or user interaction.

Affected products

  • Google Android Kernel Android Kernel

Timeline

  • 2022-03-16: disclosed: NVD Published Date
  • 2022-04-11: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-01: advisory: Vendor advisory published by Android/Google
  • 2022-04-11: exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.

Related threats